It has a clear GPL-3.0 license and a focused seven-file artifact with a README. A post-update hook and no security scanning or policy leave less operational support than newer alternatives.
42%
Total Score
50
100
83
67
The package defines a post-update-cmd script, adding install or update behavior that consumers must account for. The signal does not show that the script is unsafe, so this is a limited hygiene concern.
The latest release was published over seven years ago, with no releases in the past 12 months. This is strong evidence of abandonment risk, although the package is not registry-deprecated.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the long release gap. No newer activity is provided to offset that concern.
Composer build tooling is present, but no security-scanning tools are configured. That reduces maintenance and verification transparency for a package with no recent activity.
The repository has no security policy. This is a transparency and maintenance gap, particularly because the project shows no recent commit activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
g3n1us/datatidy Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.