Healthy and suitable to use, with a narrow maintenance risk. It has frequent recent releases, a stable version, tests, documentation, and organization backing, but recent repository work is concentrated in one contributor and the repository does not clearly mention this package in its README.
78%
Total Score
80
100
83
90
Only one registry account has publishing access, which is a concentration risk, but the organization-backed repository and active release history provide compensating evidence that this is not by itself a severe concern.
All 4 recent commits came from one contributor, creating a thin maintainer base. Organization ownership partly offsets handoff risk, but no second active contributor is shown.
The repository name does not match the package name and its README does not mention the package, so the connection between the published package and its source is less transparent. This is a genuine provenance concern despite the repository having a plausible related name.
The repository has no stars or forks and only 7 watchers. This limits community validation, though popularity is supporting evidence and the package shows independent release activity.
Composer is used as a build tool, but no security scanning tools are present. The missing scanning is a transparency gap, though it is not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
conductor/core Version ^4.0 || ^5.0 || ^6.0 | — | — |
cypresslab/gitelephant Version ^4.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.