Apache-2.0 licensing, a readable README, tests, and no install-time scripts make the release straightforward to adopt. It is very new, has no established commit history, and its three workflow actions are unpinned, so maintenance and build reproducibility remain concerns.
65%
Total Score
75
100
79
67
This is the first recorded release, published today, so there is no release cadence or longer-term maintenance record to evaluate. The repository's recent activity and organization backing provide some context but do not replace release history.
The repository has zero commits and zero active maintainers in the last three months. Because the repository was created today, this mainly reflects limited history rather than demonstrated abandonment, but long-term maintenance is still unproven.
Composer build tooling is present, but no security scanning tools were detected. The build setup is established, while security-process transparency is limited.
The repository has no security policy. This is a modest transparency gap for reporting and handling vulnerabilities, though it does not by itself indicate unsafe code.
Version v0.11.0 is a non-stable-major release, which signals an evolving interface and greater compatibility risk than a mature 1.x release. It is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^7.0 || ^8.0 | — | — |
elephentity/schema Version ^0.11 | — | — |
elephentity/codegen Version ^0.6 | — | — |
elephentity/runtime Version ^0.10 || ^0.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.