Its BSD-3-Clause license, readable package, and single runtime dependency make the small artifact easy to inspect. The repository is not archived, but its lack of a security policy leaves limited evidence for ongoing security practices.
56%
Total Score
75
100
78
83
The package has six releases but none in the last 12 months, with the latest registry release in April 2017. The repository was pushed later, which partly offsets but does not remove the stale release history.
There were no commits or active maintainers in the measured three-month period. Although the repository had a push in 2024, the recent activity window still indicates weak current maintenance.
The repository name does not match the package name and its README does not mention the package. That makes the repository association less transparent, even though a monorepo or related-project structure could explain it.
The repository has no stars or forks and only one watcher. This is weak supporting evidence, but popularity alone is not decisive for a small focused package.
The repository uses Composer build tooling, which fits the package ecosystem. No security scanning tools were detected, leaving a modest security-process gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
icanboogie/module Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.