Healthy and usable for dependency adoption, with a clear package structure, tests, stable releases, and an active organization-owned repository. The main caveats are that it is only 89 days old and all four recent commits came from one contributor, with no security policy or scanning tooling.
78%
Total Score
67
100
83
90
Four releases in 89 days, with the latest released recently and a median interval of about 28 days, show ongoing delivery; the short history still limits evidence of long-term maturity.
All four recent commits came from one contributor, creating a concentrated maintenance risk; organization ownership provides some ability to hand maintenance off, but no second active contributor is shown.
Four commits were made in the last three months, showing recent activity, but only one maintainer was active during that period, limiting evidence of durable maintenance capacity.
The repository has zero stars, forks, and watchers, so there is little external adoption evidence; this is a supporting concern rather than a decisive problem for a young, focused package.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest security-hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^2.0 | — | — |
componenta/config Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.