The package is small and has a clear MIT license, tests, and release notes. Its only release was about six months ago, with no recent commits, so maintenance remains unproven. The workflow is audited but uses two unpinned actions.
61%
Total Score
75
100
83
67
This is the package's only release, published about six months ago, so there is little release history to demonstrate sustained maintenance.
There were no commits and no active maintainers in the past three months. Combined with a single-release history, this leaves maintenance capacity uncertain.
The repository has no stars, forks, or watchers. Popularity is only supporting evidence, but the absence of any community signal provides no external confidence for this new package.
Composer build tooling is present, but no security scanning tooling was detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy. For a small package this is a minor transparency gap, but it provides no documented path for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
basketin/cart Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.