Documentation, licensing, release notes, and project ownership are all in place, with no install-time scripts. Recent repository inactivity, missing security policy, and unpinned workflow actions add maintenance and build-integrity concerns.
67%
Total Score
75
50
88
75
The package declares 12 runtime dependencies, creating a relatively broad dependency surface for consumers, though the signal does not show an unsafe or abandoned dependency pattern.
The repository recorded zero commits and zero active maintainers over the last three months. That recent inactivity is concerning despite the package's ongoing release history.
Composer build tooling is present, but no security-scanning tool was detected, leaving a security hygiene gap.
The repository has no security policy, making the process for reporting and handling vulnerabilities unclear.
Version v0.3.6 is not a stable-major release, so API compatibility may still change before 1.0; it is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
decodelabs/iota Version ^0.3 | — | — |
decodelabs/atlas Version ^0.14 | — | — |
decodelabs/lucid Version ^0.8 | — | — |
vlucas/phpdotenv Version ^5.6.2 | — | — |
decodelabs/kingdom Version ^0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.