Its README, tests, MIT declaration, and minimal dependency set make the code easy to evaluate. The organization-owned repository is intact, but it has no security policy or scanning.
65%
Total Score
75
100
86
75
This is a young package, 95 days old, with only one release and no established release cadence. That limits evidence of long-term maintenance but does not indicate abandonment by itself.
There were zero commits and zero active maintainers in the last three months. For a package only 95 days old, this is a meaningful lack of ongoing maintenance evidence.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk for a small library.
The repository has no security policy. That weakens vulnerability-reporting transparency, although the package is small and no other provided signal indicates an active security problem.
No GitHub Actions workflows were present, so there were no workflow risks to audit. This also provides no evidence of automated testing or release safeguards.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
componenta/arrayable Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.