MilliBase v2.11.0 appears to be a healthy, actively maintained dependency: it has 39 releases over 182 days, frequent recent publishing, a stable non-prerelease version, an active non-archived organization-owned repository, 73 commits in the last 3 months, and 8 merged pull requests in the last month. The repository provides tests and a changelog even though they are not included in the artifact, and it uses Composer plus Dependabot. The main reservations are the highly concentrated commit activity, install/update lifecycle scripts, absent security policy, and write-scoped workflow permissions; these warrant review but do not outweigh the strong maintenance and release evidence.
82%
Total Score
90
100
94
70
The package declares post-install-cmd and post-update-cmd scripts, which increase installation-time execution surface and merit review before adoption.
Two contributors were active, but one authored about 97.3% of the 73 recent commits, creating a concentrated maintenance risk; organization ownership partly compensates through potential handoff capacity.
The repository has 1 star and no forks or watchers. This is limited adoption evidence, but popularity is supporting evidence and does not outweigh the observed maintenance activity.
No repository security policy was found, leaving vulnerability-reporting and response guidance less transparent.
All workflows declare top-level permissions, but two have write permissions while only one is read-only; this increases CI credential impact if a workflow is compromised.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.