Clear documentation, tests, release notes, and a matching repository make the project easy to evaluate. The small maintainer base and entirely unpinned workflow actions add meaningful maintenance and build-integrity concerns.
72%
Total Score
50
94
63
post-install-cmd and post-update-cmd scripts run during dependency operations. These add some supply-chain and installation complexity, although no evidence here shows that the scripts are harmful.
The package and repository are owned by the same individual account rather than an organization. This is consistent ownership, but it does not provide organizational handoff capacity to offset the concentrated contributor base.
One contributor made 100% of the recent commits. With a user-owned project and no second active contributor shown, maintenance continuity depends heavily on one person.
The repository received 3 commits in the last 3 months from one active maintainer. Recent activity is present, but the volume is modest and concentrated.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanning layer is a modest transparency and maintenance gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fab2s/enumerate Version ^0.0.1|^0.1.0 | — | — |
fab2s/context-exception Version ^2.0|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.