Its release history is recent and the repository remains active and unarchived. Oversight is limited by one active contributor, no security scanning, and no published security policy.
67%
Total Score
75
75
50
All 3 commits in the last 3 months came from one contributor, leaving maintenance dependent on a single active developer. Organization ownership provides some handoff capacity but does not remove the concentration risk.
The repository has 0 stars and 0 forks, with 1 watcher, providing little community evidence to compensate for its concentrated maintenance.
The repository uses Composer, which supports reproducible package builds, but it has no security scanning tools. For a package distributed as reusable configuration and helper files, that is a modest transparency gap.
The repository has no security policy, so users have no documented security-reporting process. This is a governance gap, though it is not evidence of an unsafe release by itself.
Version v0.2.2 is not a prerelease, so it is presented as a stable release. Its pre-1.0 major version still signals a less mature compatibility commitment.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.