Documentation, tests, changelog, licensing, and recent commits provide a solid foundation. Maintenance depends on one contributor, while the repository has no security policy or scanning tools, so ongoing oversight is limited.
68%
Total Score
67
100
88
67
The package runs post-autoload-dump and post-install-cmd scripts. Install-time execution adds supply-chain and installation complexity, though no evidence here shows those scripts are harmful.
The repository is owned by an individual account rather than an organization. This does not invalidate the project, but it provides less visible organizational continuity for the single-maintainer profile.
The package has 102 releases in 301 days, with a median interval of about 35 minutes. This shows active publishing but also unusually rapid churn, which slightly reduces release confidence.
All 13 recent commits came from one contributor, leaving maintenance highly concentrated and creating a meaningful continuity risk.
Composer build tooling is present, but no security scanning tools are reported. This is a modest oversight gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.