Security support is limited, with no security policy or scanning, and the repository is very small with no tests. The MIT license, clear README, matching package mention, and no install scripts provide useful transparency.
62%
Total Score
50
100
88
83
The repository is owned by a user account rather than an organization, so there is no provided evidence of organizational backing to offset the thin recent activity.
The package has 9 releases, but none in the last 12 months and the latest release was about 13 months ago. This suggests maintenance may have stopped, despite the earlier rapid release cadence.
There were no commits and no active maintainers in the last 3 months, consistent with the roughly 13-month release gap. This is a meaningful abandonment concern.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning reduces maintenance transparency for a library handling OTPs.
The repository has no security policy. For an OTP library, this leaves vulnerability-reporting expectations and response guidance undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
maatify/logger Version ^1.3 | — | — |
maatify/app-handler Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.