Load .env files into Gacela
72%
Total Score
caution
Usable with caveats: maintenance is lightly evidenced, and all workflow actions are unpinned.
The package has existed since November 2022, but only four releases and one release in the last 12 months show a slow cadence. The latest release is recent, which partly offsets the limited history of active releases.
One contributor made all recent commits, creating a concentrated maintenance path. The organization-owned repository provides some handoff capacity, so this is a caution rather than a severe risk.
Only one commit was recorded in the last three months, indicating limited recent development activity. The recent push shows the project is not dormant, but the evidence of sustained maintenance is thin.
No repository security policy was found. This is a transparency gap, though it is less significant for a small configuration-reader library than for a security-sensitive component.
Version 0.4.0 is a stable, non-prerelease release, although the package remains below a stable major version. This is a modest maturity concern rather than a release-quality problem.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/dotenv Version ^6.4 || ^7.0 || ^8.0 | — | — |
gacela-project/gacela Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.