Documentation, licensing, and dependency scope are solid. The project is only about seven months old, with all three releases published within minutes and no commits in the last three months. Organization backing and security tooling provide some reassurance.
61%
Total Score
50
100
94
88
There were no commits and no active maintainers in the last three months. For a package still less than a year old, that is a meaningful sign of slowing maintenance.
The package runs a post-autoload-dump install-time script. This adds a small amount of installation complexity and supply-chain exposure, though no other provided signal shows it is harmful.
Only one registry account has publish access, which limits publishing redundancy. The repository is organization-owned, so this is a smaller concern than a lone personal project would be.
The package is about seven months old with three releases, but all three were published within minutes of one another. That shows an initial launch burst rather than sustained release activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
moox/core Version 5.0.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.