There is no declared or detected license, and the repository has no security policy or security scanning. Organization backing, a stable v1.0.0 release, and a small dependency set provide some support.
56%
Total Score
75
100
75
83
No registry license declaration, license file, or repository license file was detected. Consumers therefore lack clear licensing terms for this release.
This is the package's only release, published about 13 months ago, with no releases in the last 12 months. That limited history makes ongoing maintenance harder to establish.
The repository recorded zero commits and zero active maintainers in the last three months, despite being non-archived. This is a meaningful maintenance concern for a package with only one release.
Composer build tooling is present, but no security scanning tools were detected. The build setup is established, while automated security coverage is limited.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap, though not evidence of unsafe code by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
obelaw/twist Version * | — | — |
obelaw/contacts Version dev-main | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.