The package includes a usable README, clear release notes, and a small runtime dependency set. Its single-maintainer ownership and lack of repository security tooling leave less resilience than mature alternatives.
64%
Total Score
50
100
93
75
A single registry maintainer matches the single-user project backing, but it creates limited continuity if that maintainer becomes unavailable.
The repository had zero commits and zero active maintainers in the last three months, despite the earlier release activity; this raises concern about responsiveness and maintenance continuity.
Composer build tooling is present, but no security scanning tools were detected, leaving a repository hygiene gap for a package distributed as a dependency.
The repository has no security policy, so users have no documented private reporting path or stated security-response process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
matthiasmullie/minify Version ^1.3 | — | — |
magento-hackathon/magento-composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.