The repository lacks tests, a changelog, and a security policy, leaving maintenance and review practices thin. Organization backing, a clean MIT license, and a small dependency set reduce the concern but do not establish long-term stability.
62%
Total Score
67
100
75
75
The published artifact has no README, tests, or changelog, and the repository also reports no tests or changelog. The missing artifact tests and changelog are normal packaging practice, but the lack of repository tests is a modest maintenance concern for a library.
This package is only 41 days old and has one release, so there is little release history to establish sustained maintenance or version reliability.
One contributor made all two recent commits, creating a concentrated maintenance dependency. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only two commits were recorded in the last three months, indicating limited observed development activity; the package's recent creation partly explains this sparse history.
Composer build tooling is present, but no security scanning tool was detected, leaving security-review automation un demonstrated.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fabricate/contracts Version ^0.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.