The package includes tests, a changelog, a clear Apache-2.0 license, and a clean Composer dependency setup. Its publication history is too young to establish durable maintenance, and the repository does not explicitly mention this package.
68%
Total Score
83
100
81
83
Only two releases have appeared over roughly one day, so the package has not yet demonstrated sustained maintenance or long-term stability.
There were no commits or active maintainers in the preceding three months; because the repository was created and pushed very recently, this mainly leaves maintenance capacity unproven.
The repository name does not exactly match the package name and its README does not mention the package, leaving ownership of the published package less explicit.
Composer build tooling is present. No security scanning is configured, a modest repository hygiene gap rather than a severe dependency risk.
The repository has no security policy, reducing transparency about vulnerability reporting and handling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
conductor/application-orchestration Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.