Tests, release notes, and a matching source tree make the package easy to inspect. Its MIT license and organization ownership add useful continuity, though ongoing activity remains narrow.
70%
Total Score
67
94
75
All three-month commit activity came from one contributor, leaving no demonstrated second contributor to absorb maintenance if the primary contributor becomes unavailable.
Only one commit was recorded in the last three months, which is thin activity for a package that released eight times in the past year and raises maintenance-continuity concerns.
Composer build tooling is present, but no security-scanning tool was detected; this is a modest transparency and maintenance gap rather than a severe risk.
The repository has no SECURITY.md or other recorded security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version ^3.0 | — | — |
codemonster-ru/env Version ^2.0 | — | — |
codemonster-ru/http Version ^2.1 | — | — |
codemonster-ru/view Version ^2.0 | — | — |
psr/event-dispatcher Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.