Usable with caveats: it is a small, organized package with tests, recent commits, and a stable release, but it is only 89 days old and all recent work comes from one contributor. The missing security policy and modest release history warrant extra review before relying on it broadly.
72%
Total Score
67
100
88
90
The package is young at 89 days, with three releases and a median interval of about 45 days; this shows some release activity but provides limited evidence of long-term maintenance.
One contributor made all three commits in the last three months, creating a concentrated maintenance risk; organization ownership provides some ability to hand maintenance off but does not show that a second contributor is active.
There were three commits in the last three months, so the project is not inactive, but activity is limited for a package this new.
Composer build tooling is present, but no security scanning tools are reported, leaving a modest assurance gap.
No repository security policy is present, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
componenta/config Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.