Usable with caveats: it is actively developed, clearly licensed, and backed by a matching organization repository with tests. It is still a young package with all recent commits from one contributor and no security policy, so maintenance continuity is not yet proven.
72%
Total Score
88
50
83
88
Five runtime dependencies, including PHP, ext-sdl3, microscrap/sdl3, and scrapyard-io/tubes, create meaningful compatibility requirements for this specialized graphics integration. The profile is understandable and not unusually broad, but the native extension and ecosystem coupling narrow portability.
All 17 commits in the last 3 months came from one contributor, giving the project a very low individual bus factor. Organization backing provides some handoff capacity, but no second active contributor is shown to demonstrate that capacity in practice.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for adoption, but popularity is not required for a small, specialized package and does not outweigh its recent development activity.
Composer build tooling is present, but no security scanning tool was detected. The build setup is appropriate, while the missing scanning layer is a modest transparency gap for supply-chain maintenance.
The repository has no security policy. That does not indicate unsafe code by itself, but it leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
microscrap/sdl3 Version ^0.7.0 | — | — |
scrapyard-io/tubes Version ^0.7.0 | — | — |
fabricate/nuts-and-bolts Version ^0.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.