The MIT license, clean install metadata, and organization ownership provide a useful baseline. Its two-release history offers limited evidence of long-term stability, while the small source tree leaves little validation context.
58%
Total Score
67
75
75
The package has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README reduces consumer guidance for this library.
Only two releases have appeared over 53 days, with about 10 days between releases. That shows recent publishing activity but not enough history to establish mature maintenance.
All three recent commits came from one contributor. Organization ownership offers some handoff capacity, but no second active contributor is shown to reduce the immediate concentration risk.
The repository recorded three commits in the last three months, so there is some recent activity, but the low volume provides limited evidence of sustained maintenance.
Composer is used for builds, but no security-scanning tooling is present. For a dependency package, that is a meaningful hygiene gap, though not evidence of a defect by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fabricate/chassis Version ^0.7.0 | — | — |
fabricate/contracts Version ^0.7.0 | — | — |
fabricate/macroable Version ^0.7.0 | — | — |
fabricate/conditionable Version ^0.7.0 | — | — |
fabricate/nuts-and-bolts Version ^0.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.