It has a README, tests, release notes, and a matching source repository. Workflow references are unpinned and the repository has no security policy, so future maintenance deserves attention.
62%
Total Score
50
88
50
The package runs a post-autoload-dump lifecycle script during installation. This adds installation-time behavior that should be understood before adoption, though the signal does not show that it is harmful.
The registry namespace and repository owner match, and the source is owned by an individual rather than an organization. This is consistent ownership, but it provides less organizational continuity.
The package has only four releases since December 2020, with no release in the last 12 months and a median interval of about 397 days. This indicates a slow maintenance cadence, although the package may be intentionally stable.
There were no commits and no active maintainers in the three months measured. Combined with the absence of releases in the last year, this is evidence of quiet maintenance.
The repository uses Composer for builds, but no security scanning tool was detected. For a small package this is a hygiene gap rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fakerphp/faker Version ^1.23 | — | — |
typo3/cms-core Version ^10.4 || ^11.5 || ^12.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.