The package has tests, a clear README, MIT licensing, and recent releases with release notes. Its small maintenance base and unpinned workflow actions leave more continuity and build-integrity risk than a mature dependency.
68%
Total Score
50
100
89
67
The repository is owned by a personal user account rather than an organization, so the single-contributor and single-maintainer concentration is not offset by visible organizational backing.
One contributor made 100% of the one recent commit, leaving maintenance dependent on a single individual with no demonstrated handoff capacity.
Only one commit was recorded in the last three months, which shows some activity but a thin recent maintenance record for a dependency.
The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but these counters provide no external adoption signal.
Composer build tooling is present, but no security scanning tools were detected, leaving repository-level security checks less visible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
joby/smol-cast Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.