Usable with caveats: the release is stable, licensed, documented, and actively published, with a matching repository and recent merge activity. It is only four days old and all recent commits come from one contributor, so long-term maintenance is not yet proven.
68%
Total Score
63
100
89
90
The repository is owned by a personal user account rather than an organization, so the thin maintainer base is not visibly backed by a broader project team.
The package is very new at four days old, with three releases and a median interval of about 2.2 days. This shows active initial development but gives little evidence of sustained maintenance.
One contributor made all two recent commits, giving the project a complete single-person dependency for maintenance. No organization backing is shown to compensate for that concentration.
The repository recorded two commits in the last three months and had activity on the assessment date, but the small volume is consistent with a newly created project rather than proven ongoing maintenance.
Composer is used as the build tool, but no security-scanning tool is configured. The missing scanner is a transparency gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
liventin/base.module Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.