Its MIT license, focused dependency set, repository tests, and clear usage example reduce adoption friction. The organization-backed repository is not archived, but the absence of a security policy leaves transparency weaker.
67%
Total Score
75
100
88
75
The package has 13 releases but only one release in the last 12 months, despite being 139 days old, suggesting activity may have stopped after the initial release burst.
The repository recorded zero commits and zero active maintainers in the last three months. Because the package is young and was pushed recently, this is a maintenance concern rather than evidence of abandonment.
Composer is used as the build tool, but no security scanning tools are reported, leaving automated security hygiene less visible.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
marko/env Version self.version | — | — |
marko/core Version self.version | — | — |
marko/config Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.