The package is clearly licensed, documented, and tied to a matching organization repository. Limited security tooling and a single registry maintainer reduce resilience if maintenance stops.
70%
Total Score
67
100
88
83
Only one account has registry publishing access, which limits visible publishing redundancy, although the repository is organization-owned and this is not evidence that only one person maintains the project.
The package has existed for over 9 years with 59 releases, but only one release in the last 12 months, indicating a slower current cadence.
The repository had no commits and no active maintainers in the last three months. The recent release partially offsets this, but current maintenance activity is still thin.
Composer is used for the build, but no repository security-scanning tool was detected, leaving a transparency and monitoring gap.
The repository has no security policy, so there is no documented path for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^5.2 | — | — |
vlucas/phpdotenv Version ^5.5 | — | — |
phpmv/ubiquity-commands Version ^0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.