The repository is organization-backed, includes tests, and is not archived. Its MIT license and small dependency set help, but the missing security policy limits transparency for a reusable framework module.
58%
Total Score
75
100
71
75
The package and repository include tests, which is a small positive. However, the package has no README, leaving consumers with less documented integration guidance.
This package has only one release, published about 1 year and 8 months ago, with no releases in the last 12 months. That is a meaningful maintenance concern for a dependency.
There were no commits and no active maintainers in the last three months. Combined with the single-release history, this raises the risk of slow maintenance.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy. That reduces transparency about vulnerability reporting and handling for a package intended to be integrated into applications.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
durrbar/core-module Version ^0.0.1 | — | — |
durrbar/user-module Version ^0.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.