The package is small, clearly tied to its organization, and includes a usable README with a matching source repository. Its limited security and development tooling provide little additional assurance for future maintenance.
58%
Total Score
75
100
71
75
The package has only one release, published over four years ago, with no releases in the last 12 months. That is substantial evidence of limited ongoing maintenance.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
The repository has no stars and only two forks. This offers little supporting evidence of maturity, but popularity is not decisive for a small library.
Composer is used for the build, but no security scanning tooling is present. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, reducing transparency about how vulnerabilities would be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
thunderer/shortcode Version >=0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.