A single maintainer and unpinned workflow actions leave less room for resilient maintenance and reproducible builds. The clear README, tests, MIT license, and release notes provide useful transparency, but the project is explicitly experimental and intended only for testing.
55%
Total Score
50
100
81
50
A post-install command runs during installation, adding execution surface beyond ordinary dependency loading. No provided signal shows that this script is necessary or tightly constrained.
The package has had no releases in the last 12 months, and its latest release was in October 2022 despite the repository being pushed in February 2024. This is a meaningful maintenance concern.
The repository recorded zero commits and zero active maintainers in the last three months. Alongside the old latest release, this supports a risk of reduced maintenance capacity.
Composer is used for builds, but no security scanning tools are present. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no security policy. For a testing library that can rewrite application execution, the absence of a documented reporting process is a genuine project-hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.