Clear licensing, tests, release notes, and a repository that matches the package improve transparency. The project has little visible adoption and no security policy, while its workflow references are not pinned.
65%
Total Score
50
100
83
75
The package and repository are owned by the same individual account, so there is no organization backing to compensate for the thin maintainer base. This makes the lack of recent activity more consequential.
The package published 26 releases in one day, with a median interval of 0 days. This shows active initial packaging but not a sustained release cadence.
There were zero commits and zero active maintainers in the last three months. For a package released only in an initial burst, this is evidence of weak ongoing maintenance capacity.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but popularity alone does not outweigh the package's other health signals.
Composer is used as the build tool, but no security scanning tool was detected. The missing scanning is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
maksimovic/zend-exception Version ^2.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.