The package includes tests, a substantial README, and an organization-owned repository. Its license texts disagree, and the project has no security policy; the workflow is clean but both actions are unpinned.
65%
Total Score
67
100
81
75
The manifest declares GPL-2.0-or-later and the artifact license file is detected as LGPL-3.0, so the package is licensed but its license metadata is inconsistent and warrants verification.
The package is brand new, with 8 releases appearing within less than an hour and no meaningful long-term maintenance history yet. This limits confidence but does not by itself indicate abandonment.
All recent commits come from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown to demonstrate that resilience.
Only 2 commits from 1 active maintainer were recorded over the last 3 months. The very new repository explains some of this, but it leaves maintenance capacity unproven.
The project uses Composer, but no security-scanning tool was detected. For a new package that runs development tooling, this is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.4 || ^8.0 | — | — |
sebastian/diff Version ^6.0 || ^7.0 || ^8.0 | — | — |
typo3/cms-core Version ^14.0 | — | — |
overtrue/phplint Version ^9.7 | — | — |
a9f/typo3-fractor Version ^0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.