The release is MIT-licensed, stable, and has a recent release with linked notes. Its small repository has no recent commits, no security policy or scanning, and the included README describes Plates rather than this package.
55%
Total Score
50
100
83
50
The package runs a post-install command, which adds installation-time behavior that consumers must account for. No provided signal shows that this script is unsafe, so this is a limited caution rather than a severe risk.
A README and release notes are present, but the excerpt describes the vendored Plates project and its Composer package rather than this package, weakening documentation transparency. Missing tests and a changelog are normal for a published artifact and are not concerns here.
The repository is owned by a user account rather than an organization, providing limited visible project backing. The matching registry namespace and repository owner offer some continuity but not a broad maintainer base.
There were no commits and no active maintainers in the last three months. For a package released recently, that is a meaningful maintenance concern and raises the risk of stalled fixes.
There are no open issues or pull requests and no activity in the last month. The clean tracker is not inherently negative, but it offers little evidence of an active maintenance community.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/plates Version ^3.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.