Tests, a clear license, and no install-time scripts reduce adoption risk. One maintainer and no security policy leave limited maintenance capacity and security oversight for future changes.
62%
Total Score
50
86
75
Only one registry account, Martin Gamboa, can publish the package. Because the project is user-owned rather than organization-backed, this indicates a thin publishing and maintenance base.
The package has 66 releases since December 2022, but none in the last 12 months; its latest release was about 18 months ago. This suggests maintenance has stopped or slowed substantially.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the roughly 18-month gap since the last push. This raises abandonment risk.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a security-hygiene gap, though it is not evidence of maliciousness.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. This weakens transparency and security response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^10.0.0 | — | — |
gamboa.martin/test Version ^5.0.0 | — | — |
gamboa.martin/errores Version ^6.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.