Documentation, tests, and a matching source repository make the package easier to adopt. Its security process is light, and the unusually compressed release history leaves maintenance maturity unproven.
62%
Total Score
50
100
75
88
The package is owned by a personal user account rather than an organization. Combined with the absence of recent recorded commit activity, this provides no organizational maintenance cushion.
The package published 30 releases within its first day, with a median interval of 0 days. This shows active initial publishing but not a proven, sustainable maintenance cadence.
No commits and no active maintainers were recorded in the preceding three months. Because the repository is newly published, this may reflect limited history, but it leaves ongoing maintenance capacity unproven.
The repository has zero stars, forks, and watchers. For a package released within the same day, this is weak supporting evidence rather than a standalone health problem.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap, not evidence of unsafe code by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.30 | — | — |
simonhamp/the-og Version ^0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.