The repository clearly matches the package and is backed by an organization, which gives the small project useful ownership context. Its create-project installer and README fit the package's template role.
52%
Total Score
75
58
75
The manifest declares the package proprietary, with no detected license and no license file. That creates a material legal and transparency concern for a package intended to be used as an open-source dependency.
All five releases appeared within roughly 6 minutes on the first release day, and there has been no later release during the package's 137-day lifetime. This suggests an immature release history rather than an established maintenance cadence.
The repository recorded zero commits and zero active maintainers during the last three months, despite being only 137 days old. That is a meaningful maintenance and abandonment concern.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and supply-chain hygiene gap, not evidence that the package is unsafe.
The repository has no security policy. For a small, newly released project this reduces clarity about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
model/core Version ^0.4 | — | — |
model/assets Version ^0.4 | — | — |
model/router Version ^0.2 | — | — |
model/settings Version ^0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.