The package is clearly licensed, tested in the repository, and has regular releases. Read-only workflow permissions help, but unpinned actions and no security policy reduce confidence.
65%
Total Score
83
75
50
The package is only 56 days old, with three releases and a median interval of about 10 days. This shows active early development, but provides limited evidence of long-term maintenance.
One contributor made all seven recent commits, concentrating current maintenance knowledge in a single person. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of adoption signals provides little external evidence of maturity for this very young package.
Composer build tooling is present, but no security scanning tool was detected. That leaves security-quality checks less visible than they could be.
The repository has no published security policy. For a package integrated into application infrastructure, this weakens the documented process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.7 | — | — |
cakephp/queue Version ^2.3 | — | — |
cakephp/cakephp Version ^5.4 | — | — |
symfony/polyfill-php84 Version ^1.31 | — | — |
crustum/plugin-manifest Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.