Usable with caveats: the release is well-scaffolded, licensed, and backed by an active-looking organization repository, but it is brand new and has no recorded commit activity yet. Treat it as an early-stage dependency until its maintenance history develops.
68%
Total Score
75
100
78
90
This is the first release and the package is 0 days old, so there is no demonstrated release cadence or long-term maintenance record.
No commits or active maintainers were recorded in the last 3 months. Because the repository and release are brand new, this is partly explained by limited history, but ongoing maintenance is not yet demonstrated.
The repository has no stars, forks, or watchers. For a package released today this is expected and is only weak negative evidence, but there is no external adoption signal yet.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest security-process gap for a package intended for dependency use.
The repository has no security policy, which weakens disclosure guidance and transparency for future vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
particle-academy/fancy-connector-core Version >=0.8.0 <2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.