The source is compact and the package has no install-time scripts. Organizational backing and a clean workflow audit help, but there is little evidence of long-term maturity.
62%
Total Score
67
100
71
75
The package and repository have no README, while tests and a changelog are absent in the source; the latter are normal for published artifacts, but missing consumer documentation is a minor transparency gap for a library.
The package is only 41 days old and has one release, so there is not yet enough release history to demonstrate sustained maintenance.
One contributor made all recent commits, creating a concentrated maintenance path; organization backing partly offsets the risk but no second active contributor is shown.
Only 2 commits were recorded in the last 3 months, indicating limited observed maintenance activity; the repository is organization-owned, which provides some support capacity.
Composer is used for builds, but no security-scanning tooling was detected, leaving a modest gap in ongoing project hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fabricate/contracts Version ^0.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.