The repository has tests, substantial documentation, active contribution from two developers, and organizational backing. Install-time scripts, missing security scanning, and unpinned workflow actions add maintenance and build-integrity concerns.
68%
Total Score
100
79
50
The package runs post-install and post-update Composer scripts, adding execution during dependency installation or update. This is common for framework tooling but increases the trust and maintenance surface.
The package is less than one day old, with 8 releases and a median interval of about 9 minutes. This shows active initial development but provides almost no evidence of sustained release stability.
The project uses Composer and Make, but no security-scanning tools were detected. That is a modest transparency and maintenance gap for a framework package.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented. This lowers transparency but is not evidence of abandonment by itself.
Version v0.2.5 is not a stable major release, so its public API and behavior may still change substantially. It is not marked prerelease, which modestly offsets that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ereborcodeforge/mazarbul Version ^1.0 | — | — |
ereborcodeforge/durin-core Version ^0.1 | — | — |
ereborcodeforge/mithrilphp Version ^2.2 | — | — |
ereborcodeforge/durin-presets Version ^0.2.1 | — | — |
ereborcodeforge/durin-architecture Version ^0.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.