Healthy and actively maintained, with a strong release history and a current source repository. The main caveats are that all recent commits come from one maintainer and the repository has no security policy or automated security scanning.
78%
Total Score
63
100
94
88
The package and repository are owned by the same individual account, which supports ownership alignment but provides no organizational backing to offset the single-maintainer risk.
One contributor made all 42 commits in the last 3 months, leaving no demonstrated backup maintainer and increasing continuity risk if that person becomes unavailable.
The repository received 42 commits in the last 3 months, but only one maintainer was active during that period. The activity is strong, while the narrow maintainer base remains a maintenance risk.
Composer build tooling is present, but no security-scanning tool was detected, leaving a gap in automated security hygiene.
The repository has no security policy, so the project does not document a clear process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
foxy/foxy Version ^1.1.0 | — | — |
mlocati/ip-lib Version ^1.20 | — | — |
mongodb/mongodb Version ^2.3 | — | — |
erusev/parsedown Version 1.8.* | — | — |
capile/tecnodesign Version ^3.0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.