A clear license, repository tests and changelog, and only two runtime dependencies make the package easier to assess. Its tiny community and absent security policy leave less evidence for long-term support.
62%
Total Score
50
100
88
50
post-install-cmd and post-update-cmd scripts run during dependency operations, adding execution-time supply-chain exposure beyond ordinary package installation.
The repository recorded no commits and no active maintainers during the last three months, leaving current maintenance capacity uncertain despite recent releases.
There were no new or closed issues or pull requests in the last month, and no open work is visible, providing little evidence of an active user or contributor community.
The repository has only 2 stars, 0 forks, and 1 watcher, so the project has limited independent visibility and community redundancy.
Composer build tooling is present, but no security scanning tooling was detected, reducing automated security coverage.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
duanestorey/crossroads-core Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.