A single maintainer and no security scanning limit confidence, while the linked repository and MIT licensing provide basic transparency. The post-update install script warrants extra review before adoption.
54%
Total Score
50
83
50
A post-update command runs during dependency updates, adding execution behavior that consumers should understand; this is a manageable supply-chain hygiene concern.
One registry maintainer is a limited publishing base, although the linked repository belongs to the same individual and matches the package.
Only two releases exist, with none in the last 12 months; the latest was published in February 2024, indicating a long period without registry maintenance.
The repository recorded no commits and no active maintainers during the last three months, consistent with the package's extended release gap.
The repository has zero stars and forks and only one watcher, providing little supporting evidence of broad community review; popularity is only secondary evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bravedave/dvc Version * | — | — |
bravedave/green Version * | — | — |
giggsey/libphonenumber-for-php Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.