The small codebase includes tests, an MIT declaration, and no install scripts, which reduces adoption friction. It has no README or security policy, and its minimal public traction offers little additional confidence.
42%
Total Score
100
61
67
Only two releases were published, both in June 2021, with no release in roughly five years. That is strong evidence of abandonment risk despite the package not being deprecated.
The package and repository contain tests, which is useful evidence of basic validation. The missing README reduces consumer transparency for a library, while the absent changelog is normal because release notes for this version are not provided.
The repository name does not match the package name, and no README package mention was collected. That weakens confidence that the linked repository is the package's clearly identified home.
The repository has zero stars and forks and one watcher. Popularity is not required for a healthy small package, but these counters provide no supporting evidence of active community use.
Composer is used as the build tool, but no security-scanning tooling is reported. For this small package that is a minor transparency gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gvera/config Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.