This release appears suitable to depend on: it is actively maintained, has a stable v1.5.0 release, a non-deprecated registry entry, a matching organization-owned repository, clear licensing, substantial source and documentation, and recent release and commit activity. The main concerns are that all recent repository commits come from one contributor, the package runs a post-autoload-dump lifecycle script, the repository lacks a security policy, and its GitHub popularity is currently negligible; these warrant review but do not outweigh the evidence of active development and release hygiene.
82%
Total Score
80
100
94
70
The package defines a post-autoload-dump install-time script, which adds execution during installation and merits review even though no broader script risk is shown.
Only one registry account has publishing access, which is a limited publishing-control base; however, this is partly mitigated by the linked repository being owned by the NexusPHP organization.
One contributor made all 14 commits during the last 3 months, creating a low individual bus factor; organization ownership provides some capacity for handoff but does not eliminate concentration risk.
The repository has zero stars, forks, and watchers, so there is little external adoption evidence; popularity is supporting evidence and does not override the observed release and commit activity.
No SECURITY.md or equivalent security policy was found, reducing vulnerability-reporting transparency; this is a hygiene gap rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.