Astral Starter — application from scratch (auth, admin, layout simple) basée sur astral-core
68%
Total Score
caution
Only eight days old, with two commits from one contributor and no security policy, so long-term maintenance remains unproven.
The registry namespace and repository owner match, but the owner is identified as a GitHub user rather than an organization. The ownership relationship is clear, while institutional backing is not demonstrated.
The package is only 8 days old, with 3 releases and a median interval of about 4 days 11 hours. That shows active initial iteration but provides little evidence of sustained maintenance.
One contributor accounts for all 2 commits in the last 3 months, creating a concentrated maintenance dependency. The matching project ownership provides some context but does not remove the lack of demonstrated backup capacity.
Only 2 commits were recorded in the last 3 months, all within this very new project. Recent activity exists, but the small volume does not yet demonstrate durable maintenance.
Composer build tooling is present, but no security-scanning tools were detected. For an application starter handling authentication and users, that is a meaningful hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
astral-php/astral-core Version ^1.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.