Usable with caveats: the package is transparent and tested, but it has had only one release and no commits for more than five years. Treat it as stable legacy code and verify that its PHP and dependency requirements still fit your project.
58%
Total Score
50
100
69
75
Composer post-install and post-update scripts run during dependency operations. Their presence deserves review because install-time code increases operational exposure, although this signal alone does not show that the scripts are dangerous.
This is the only release, published about 8 years and 9 months ago, with no releases in the last 12 months. The long absence of releases is a meaningful maintenance concern.
There were no commits and no active maintainers in the last three months, indicating the project is currently inactive and increasing abandonment risk.
The repository has zero stars and forks and only one watcher. This is weak supporting evidence of limited adoption, but popularity alone is not decisive for a small library.
Composer build tooling is present, but no security-scanning tools were detected. This is a transparency and assurance gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hollodotme/crontab-validator Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.