demai/config 1.0.0 has solid basic packaging and transparency: it is licensed, includes a substantial README, source tests, a complete-looking 41-file tree, Composer build metadata, and no install-time scripts or registry deprecation. However, this is a newly published package with only one release, one commit and one active contributor in the observed three-month window, no stars or forks, and no security policy. It may be usable, but its maintenance track record and contributor resilience are not yet established, so adopting it carries moderate abandonment and support risk.
64%
Total Score
60
100
78
90
Only one registry account has publish access. This is not a direct measure of development activity, but it leaves publishing continuity dependent on a single person.
The repository is owned by an individual user rather than an organization, so there is no organizational backing signal to offset the narrow maintainer and contributor base.
The package is only 0 days old with one release and no established release cadence, so long-term maintenance and compatibility are unproven.
One contributor made 100% of the observed commits, creating a concentrated maintenance dependency with no demonstrated handoff capacity.
Only one commit was recorded in the last three months from one active maintainer. The recent repository push and merged pull requests show initial activity, but sustained maintenance is not yet demonstrated.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.