This is a generally healthy package to depend on: it is a stable MIT-licensed release, not deprecated or archived, is backed by a matching organization-owned repository, and has clear documentation, security policy, and restrictive workflow permissions. The main concerns are modest maintenance and maturity signals: only four releases over roughly three and a half years, one release in the last 12 months, no commits or active maintainers in the last three months, no tests in either the artifact or repository, and no automated security-scanning tool. These concerns warrant monitoring but do not outweigh the recent release and repository activity, coherent package contents, and organizational backing.
78%
Total Score
88
100
78
100
The package has a substantial README and uses GitHub Releases, but neither the artifact nor repository contains tests or a changelog. The missing tests are a genuine maintenance and regression-risk gap for a library package, while the documentation provides useful compensating transparency.
The package is about 1,259 days old with four releases, a median interval of about 224 days, and one release in the last 12 months. The recent release is positive, but the sparse cadence indicates limited ongoing maintenance capacity.
There were zero commits and zero active maintainers in the last three months, which is a concrete recent-maintenance gap. The same-period merged pull request and the release/repository push provide partial compensation, so this is caution rather than danger.
The repository has zero stars and forks and only two watchers, indicating a small user and contributor footprint. Popularity is supporting evidence rather than a verdict, so this lowers confidence in broad community resilience but is not independently severe.
Composer build tooling is present, but no security-scanning tools were detected. Build support is healthy; the absent scanning automation is a moderate transparency and security-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
charcoal/app Version ^4.0 || ^5.0 | — | — |
charcoal/core Version ^4.0 || ^5.0 | — | — |
charcoal/view Version ^4.0 || ^5.0 | — | — |
charcoal/object Version ^4.0 || ^5.0 | — | — |
charcoal/factory Version ^4.0 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.