Healthy and suitable to use, with a clear license, tests, regular releases, and an active unarchived repository. The main caveats are that all recent commits come from one contributor and the repository does not clearly mention this package.
78%
Total Score
83
100
88
83
One contributor made all five commits in the last three months, creating a meaningful continuity risk. Organization backing provides some ability to transfer maintenance, but no second active contributor is shown.
The repository name does not exactly match the package name and its README does not mention the package, so the linkage is less transparent than ideal. The repository naming is plausibly a subpackage convention, but the missing README reference remains a caution.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and process gap, though it is not by itself evidence that the package is unsafe.
The repository has no SECURITY.md or other detected security policy, reducing clarity about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
conductor/core Version ^4.0 || ^5.0 || ^6.0 | — | — |
azure-oss/storage-blob-flysystem Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.