MIT licensing, frequent releases, and a clear package tree support adoption. A single recent contributor and no security policy leave maintenance ownership less resilient.
72%
Total Score
67
100
50
Composer post-install and post-update scripts run automatically, adding installation-time behavior that consumers should understand before adoption.
One contributor made all seven recent commits, giving the project a concentrated maintenance base; organization ownership provides some handoff capacity but no second active contributor is shown.
Seven commits were made in the last three months, showing recent activity, although all activity comes from one maintainer.
No repository security policy is present, leaving vulnerability reporting and response expectations undocumented.
Both workflows were analyzed successfully with no audit findings or untrusted checkouts, but all six action references are unpinned, reducing build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drago-ex/application Version ^2.0 | — | — |
drago-ex/project-front Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.