The focused four-file artifact includes a README and tests, and organization backing provides useful project context. The missing license and absent security policy leave important project assurances unclear.
57%
Total Score
67
100
75
88
No declared license, license file, or repository license file was detected. This creates a meaningful adoption and redistribution concern with no provided evidence compensating for it.
The package has had no releases in the last 12 months, and its latest release was over two years ago. The 10-release initial burst shows prior activity but does not offset the prolonged pause.
There were no commits and no active maintainers in the last three months, consistent with the package's broader lack of releases for over two years. Organization backing does not compensate for absent recent activity.
There are no open issues or pull requests, and no recent issue or pull-request activity was recorded. This is compatible with a small stable package but provides no evidence of ongoing maintenance.
Composer build tooling is present, but no security scanning tool was detected. The small package and test coverage help, but the missing security automation is still a transparency gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
codelytv/criteria Version ^0.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.