Glueful API Application Skeleton — Create high-performance APIs
82%
Total Score
80
100
89
80
The package runs a post-create-project-cmd lifecycle script during project creation. This is relevant operational and supply-chain exposure for a starter package, although the single named script is not by itself evidence of an unhealthy release.
Only one registry account has publish access. This is a limited publishing base, but the repository is owned by the Glueful organization, which provides some organizational backing rather than leaving the package entirely unaffiliated.
One contributor made all 43 attributed commits in the last three months, creating a real continuity risk. The organization-owned repository offers some potential handoff capacity, but no second active contributor is shown.
The repository has only 1 star and 0 forks, indicating limited external adoption or review. Popularity is supporting evidence rather than a verdict, so this is a modest concern rather than a severe risk.
Composer is used as a build tool, which fits the package ecosystem, but no security scanning tools are configured, leaving a security-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
glueful/media Version ^1.1.0 | — | — |
glueful/users Version ^2.3.2 | — | — |
glueful/framework Version ^1.83.3 | — | — |
glueful/email-notification Version ^1.12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.