The project has no security scanning or security policy, and its 15 releases arrived in about one day. Its small, matching repository and clear README help, but there is little evidence of sustained maintenance yet.
62%
Total Score
78
75
All 15 releases were published within about one day, with a median interval of roughly 12 minutes, and the latest release was 99 days ago. This suggests an immature release burst rather than an established maintenance cadence.
The repository has zero stars, forks, and watchers. Popularity is not required for a healthy small package, but there is no community adoption evidence to compensate for the limited maintenance history.
Composer is used for builds, but no security-scanning tool was detected. That leaves dependency and build-risk checks less transparent for a package intended for application integration.
The repository has no security policy. For a small client library this is a modest transparency gap, but it provides no documented process for reporting or handling vulnerabilities.
Version 0.0.15 is not a stable-major release, so the public API may still change substantially. It is not marked prerelease, which partly offsets the concern but does not establish maturity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lotcz/zavadil-php-common Version ^3.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.