This release appears healthy and suitable to depend on: it has a mature release history dating from 2020, 49 releases with 18 in the last 12 months, a stable non-prerelease version, no registry deprecation, recent repository activity, organization backing, and limited dependency and workflow risk. The main concerns are that all recent commits come from one bot, the repository does not explicitly match or mention the package name, and the release workflow lacks declared top-level token permissions; these reduce transparency and resilience but are partly offset by the organization-owned repository, active releases, Dependabot, and the package's clearly documented role as a distribution artifact for compiled assets. The absent tests and changelog are not material for this asset-only package, though the missing security policy remains a modest hygiene gap.
82%
Total Score
70
100
94
80
One contributor, az-digital-bot, made all six commits in the last three months, giving a 100% top-contributor share. Organization backing mitigates handoff risk, but no second active contributor is evidenced in this signal.
The repository recorded six commits in the last three months, showing recent activity, but all were produced by only one active maintainer. Activity is present rather than collapsed, though its resilience is limited.
There are no open issues and six open pull requests, but no issues or pull requests were newly created or merged during the last month. The open pull requests show some activity, while the lack of recent closures is a modest process concern.
The repository name does not match the package name and its README does not mention the package. Because this can make package-to-source provenance less transparent, it is a caution, although the repository URL and README identify it as the Packagist distribution repository for Arizona Bootstrap.
No security policy is present in the repository. This is a transparency and vulnerability-reporting gap, though it does not by itself indicate abandonment for a small asset distribution package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.