Healthy and suitable to use, with a concentrated maintenance base as the main caveat. It has recent stable releases, tests, release notes, an active unarchived repository, and no risky workflow patterns, but all recent commits come from one contributor and the repository lacks a security policy.
78%
Total Score
88
100
89
80
One contributor made all seven commits in the last three months, leaving no demonstrated handoff capacity. Organization backing reduces the severity, but the concentration remains a maintenance risk.
The repository has zero stars and two forks. This indicates limited public adoption, but popularity is supporting evidence and does not outweigh the recent releases, tests, and organizational backing.
The project uses Composer for builds, but no security-scanning tool was detected. Build tooling is present; the missing scanning is a modest transparency and maintenance gap.
The repository has no security policy. For a package that manages database schemas and is intended for application use, the lack of documented vulnerability-reporting guidance is a genuine transparency gap.
Neither workflow declares top-level token permissions, though neither declares top-level write access and the workflows show no dangerous patterns. This is a minor hardening gap rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
leafs/fs Version ^5.0 | — | — |
leafs/date Version ^5.0 | — | — |
leafs/sprout Version ^5.0 | — | — |
symfony/yaml Version * | — | — |
fakerphp/faker Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.