Release cadence remains regular, with a documented release and a maintained repository structure. The organization-backed project is workable, but security process visibility is limited.
68%
Total Score
75
50
88
83
Nine runtime dependencies create a relatively broad dependency surface for a small package, though the profile is explicit and includes the required PHP runtime.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful maintenance warning that is partly offset by the recent release history and push date.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest visibility gap.
The repository has no security policy, making vulnerability-reporting expectations and response procedures less transparent.
Version v0.3.3 is not marked prerelease, although the package remains below a stable major version, so some API change risk remains.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
decodelabs/atlas Version ^0.14 | — | — |
decodelabs/lucid Version ^0.8 | — | — |
decodelabs/kairos Version ^0.2 | — | — |
decodelabs/monarch Version ^0.2 | — | — |
decodelabs/coercion Version ^0.3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.