62%
Total Score
caution
Usable with caveats: recent releases support it, but maintenance and security coverage are thin.
The repository is owned by an individual user rather than an organization, so the project has limited visible institutional backing.
There were no commits and no active maintainers in the last three months. This is a meaningful maintenance concern, although the repository had a release and push on January 7, 2026.
Composer build tooling is present, but no security scanning tools were detected. For a package executed through Composer, that leaves a real security-hygiene gap.
The repository has no security policy, so there is no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cweagans/composer-patches Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.