It has tests, a clear MIT license, stable versioning, and no install-time scripts. The lack of commits or releases for two years makes future fixes uncertain, while the tiny project footprint and absent security tooling add modest concern.
58%
Total Score
25
100
78
75
There were zero commits and zero active maintainers in the last three months, consistent with the two-year release gap and indicating limited current maintenance capacity.
The package and repository use matching coco-project ownership namespaces, but the repository owner is a user account rather than an organization; this provides limited backing evidence.
The latest release was published two years ago, with no releases in the last 12 months; the five-release history shows a small, now-stalled project.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but this offers little evidence of a broad review or support community.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap for a package with no recent activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/lock Version ^5.4 | — | — |
lorisleiva/cron-translator Version ^0.4.5 | — | — |
coco-project/command-builder Version ^1.0 | — | — |
dragonmantank/cron-expression Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.