The MIT license, matching repository, README, tests, and release notes provide useful transparency for consumers. Workflow references are unpinned and no security scanning or policy is present, while the repository currently shows no recent commit activity.
65%
Total Score
50
50
88
75
Five runtime dependencies, including Sentry, dotenv, and Parsedown, make the package depend on a nontrivial supply chain; no dev dependencies are declared, so this is a moderate rather than severe concern.
The repository recorded zero commits and zero active maintainers over the last three months. The recent release partly offsets this, but the lack of ongoing source activity raises maintenance risk.
The repository has one star and no forks, indicating limited external adoption and review. Popularity is supporting evidence rather than a verdict, so this is only a mild concern.
Composer is used for the build, but no security scanning tools are configured, leaving less automated protection against dependency or build issues.
The repository has no security policy, reducing transparency about how users should report and receive fixes for vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ecxod/lang Version ^1.0 | — | — |
sentry/sentry Version ^4.8 | — | — |
erusev/parsedown Version ^1.7 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.