The repository includes tests, a readable README, and an MIT license. Twelve runtime dependencies, no security policy, and a post-update script increase maintenance and transparency concerns.
42%
Total Score
25
50
75
50
This is the only release, published about 20 months ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a package intended as an application library.
There were no commits and no active maintainers in the last 3 months. Combined with the single-release history, this materially raises abandonment risk.
The package declares 12 runtime dependencies, including several related packages from the same publisher. This creates meaningful maintenance and compatibility exposure, especially for a package with little observed update activity.
A post-update command runs during dependency updates. Lifecycle scripts add operational and supply-chain exposure because package-manager actions can execute project-defined code.
The package and repository are owned by the same individual account. That is consistent ownership, but it also indicates a limited organizational backing structure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
julio101290/auth Version ^1.0 | — | — |
phpcfdi/sat-catalogos Version ^0.3.1 | — | — |
codeigniter4/framework Version ^4.1 | — | — |
julio101290/boilerplate Version ^1.0 | — | — |
codeigniter4/translations Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.