The source repository is active, but all recent commits come from one contributor and the release history is unusually compressed. The package includes a license and consumer documentation, yet those strengths do not offset the maintenance and adoption risk.
20%
Total Score
75
69
50
Packagist marks the entire package as abandoned, with no replacement identified. Package-level abandonment is a severe adoption risk even though the repository remains accessible.
The package runs post-install and post-update Composer scripts. These increase installation complexity and execution exposure, though the signal alone does not establish that the scripts are unsafe.
The package has 73 releases in 270 days, with a median interval of about 45 minutes. This unusually compressed cadence suggests a rapidly changing and immature release process rather than established stability.
One contributor made 100% of the 69 commits in the last 3 months. With user-owned project backing, this leaves a material continuity and abandonment risk.
Composer is used as a build tool, providing basic project tooling, but no security-scanning tool was detected. The absence of automated security scanning is a modest hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
luxid/rocket Version ^0.2.1 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.