MIT licensing and an organization-owned repository provide useful transparency. The package is still early-stage, with limited activity and little documented project hygiene.
59%
Total Score
67
75
75
The artifact has no README, while tests and a changelog are absent both from the package and repository; missing tests and changelog are normal for published artifacts, but the missing consumer-facing README reduces transparency for a library.
The package is only 56 days old and has two releases, with releases about two weeks apart. This shows some activity but provides limited evidence of long-term maintenance.
One contributor made all three recent commits, creating a concentrated maintenance risk. Organization backing partly compensates because the project can potentially hand work to another maintainer.
Only three commits from one active maintainer were recorded in the last three months. That demonstrates recent activity but gives little evidence of sustained maintenance capacity.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a hygiene gap rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.7 | — | — |
symfony/process Version ^7.4.5 || ^8.0.5 | — | — |
fabricate/chassis Version ^0.7.0 | — | — |
fabricate/console Version ^0.7.0 | — | — |
fabricate/pipeline Version ^0.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.