The package has a clear README, release notes, an MIT license, and recent repository activity. It lacks a security policy and automated security scanning, leaving limited documented security oversight.
72%
Total Score
67
100
94
83
One contributor made 100% of the recent commits. Organization ownership provides some handoff capacity, but no second active contributor is visible in the collected activity.
Four commits in the last three months show some ongoing work, but all activity comes from one active maintainer, limiting visible maintenance capacity.
Composer build tooling is present, but no security-scanning tools were detected, leaving an important part of project oversight uncovered.
The repository has no security policy, so users are not given a documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
codemonster-ru/mail Version ^1.0 | — | — |
codemonster-ru/cache Version ^1.0 | — | — |
codemonster-ru/queue Version ^1.0 | — | — |
codemonster-ru/events Version ^1.0 | — | — |
codemonster-ru/annabel Version ^1.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.