This is a well-documented, actively developed young package with strong artifact and repository hygiene: it has a license and NOTICE files, tests, a changelog, CI workflows, a security policy, recent releases, and no deprecation or archive indicators. The main concerns are its short 60-day history, pre-1.0 versioning, and substantial maintainer concentration: all 14 recent commits came from one contributor, despite organization ownership providing some handoff capacity. The repository also lacks automated security-scanning tools and grants top-level write permissions to three workflows, which warrants review of the release and documentation automation before adoption. Overall, it appears usable and transparently maintained, but it has not yet demonstrated long-term stability or a broad maintenance base.
78%
Total Score
88
100
78
90
Seven releases in the first 60 days, with a median interval of about 2 days, demonstrates active publishing, although the short history does not yet establish long-term maintenance.
One contributor made all 14 commits in the last three months, creating a real continuity risk; organization ownership partially compensates because maintenance can potentially be handed off within the organization.
The repository has zero stars, forks, and watchers. This limits external validation, but popularity is supporting evidence and the package's direct maintenance signals are stronger than this absence.
Composer build tooling is present, but no security-scanning tools were detected. This is a hygiene gap, though the repository's security policy and workflow-risk results provide partial compensation.
All workflows declare permissions, but three workflows grant top-level write access. Explicit permissions are better than undeclared defaults, yet broad write capability increases the impact of workflow compromise and merits review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
milpa/core Version >=0.6.2 <1.0 | — | — |
doctrine/orm Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.