The package is small, clearly documented, tested, and backed by an organization. Its narrow dependency set and clean publication metadata reduce adoption friction, but its short history limits confidence in long-term maintenance.
64%
Total Score
75
100
79
83
The package is only 171 days old and has two releases, both published on the same day, so there is little release history to demonstrate sustained maintenance.
The repository recorded zero commits and zero active maintainers during the past three months. Because the package is young and its releases were concentrated on one day, this leaves ongoing maintenance unproven.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy. For a small library this is a limited disclosure and maintenance gap, but it reduces clarity about how vulnerabilities would be handled.
Version v0.1.1 is below a stable major release, which signals an early-stage API; the package is not marked as a prerelease, partly offsetting that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
liquidrazor/event-manager Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.