The package includes tests, a matching source repository, and a stable MIT declaration. Install and update hooks add some operational risk, while the single release and no recent commits leave maintenance uncertain.
58%
Total Score
50
100
88
50
post-install-cmd and post-update-cmd scripts run during dependency operations, creating extra installation behavior that developers should understand before adopting it.
The repository owner is an individual account rather than an organization, so the single registry maintainer does not show broader organizational backing.
This is the only release, published 340 days ago, so there is no demonstrated release cadence or evidence of ongoing evolution.
There were zero commits and zero active maintainers in the last three months, which weakens confidence that issues or compatibility changes will be addressed.
The repository uses Composer, but no security scanning tools were detected, leaving a modest security-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version * | — | — |
pagarme/pagarmecoreapi Version v5.6.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.