Usable with caveats: the package is actively releasing, backed by an organization, and its repository is current with substantial test coverage. It is only 35 days old, has one recent contributor, and lacks security scanning and a security policy, so maintenance depth is not yet proven.
68%
Total Score
63
100
78
90
The package is only 35 days old but has 50 releases, including releases within the last day, showing strong current activity while leaving little evidence of long-term maturity.
All recent commit activity comes from one contributor, creating concentration risk. The organization-owned repository partly compensates because maintenance can potentially be handed off within the project.
Only one commit from one active maintainer was recorded in the last three months, despite the repository being recently updated, so ongoing maintenance capacity is not yet demonstrated.
There are no open issues or pull requests and no recent issue or pull-request activity. This does not show neglect by itself, but it provides little evidence of an active user and maintainer feedback loop.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but the package is only 35 days old and organization backing makes low public popularity less decisive.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lattice-php/ui Version self.version | — | — |
lattice-php/core Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.