Usable with caveats: the package is young and has only two releases, with all recent repository work coming from one contributor. Organization backing, a matching repository, an MIT license, and no deprecation or install scripts provide useful safeguards, but the missing README and security policy reduce transparency.
62%
Total Score
67
100
75
50
The published artifact has no README, which makes a small library harder to understand and integrate; absent tests and changelog files are expected packaging gaps and are not penalized here.
The package is only 55 days old with two releases, although the releases are about 15 days apart and show an initial maintenance cadence.
One contributor made all three recent commits, creating a concentrated maintenance dependency; the organization-owned repository provides some ability to hand off maintenance.
There were three commits in the last three months, showing recent work, but the activity is light for a package intended to be depended on.
Composer is used as a build tool, which is appropriate for this PHP package, but no security scanning tooling was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fabricate/contracts Version ^0.7.0 | — | — |
fabricate/collections Version ^0.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.