Composer plugin that detects patches.lock.json changes and triggers re-patching of affected packages.
64%
Total Score
75
100
88
75
The package is 194 days old with only two releases, both published on the same day, leaving little evidence of a sustained release cadence.
There were zero commits and zero active maintainers in the last three months, a meaningful maintenance concern for a package only 194 days old.
The repository uses Composer build tooling, but it has no security scanning tools; this is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, reducing the available disclosure guidance for consumers, though this small plugin is not thereby unfit to use.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cweagans/composer-patches Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.