This release appears healthy and suitable for dependency use: it has a long release history with 162 releases, 33 releases in the last 12 months, a stable non-prerelease version, recent repository activity, an active non-archived source repository, tests, a matching repository reference, and clear licensing. The main concerns are that all 16 recent commits came from one contributor, the repository has no security scanning or security policy, and the package lacks a changelog; these are meaningful transparency and resilience gaps, but the organization-owned repository, ongoing release cadence, and existing tests provide substantial compensating evidence.
78%
Total Score
90
100
89
90
All 16 recent commits came from one contributor, creating a genuine continuity risk. Organization ownership provides some handoff potential, but no second active contributor is shown in this signal.
The repository has only 2 stars, 0 forks, and 1 watcher, indicating limited external adoption. Popularity is supporting evidence rather than a verdict, so this is a modest caution rather than a severe risk.
Composer build tooling is present, but no security scanning tools are configured. This lowers security-process transparency, though it does not by itself indicate abandonment or unsafe code.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability reporting and response expectations less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getpop/engine Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.