The project has a long release history, recent publishing, tests, and a clear license. The linked repository does not identify or mention this package, while one-person maintenance, no recent commits, and no security policy leave meaningful transparency and continuity concerns.
62%
Total Score
50
100
81
75
Only one account has registry publishing access, and the project is owned by an individual rather than an organization. The active release history partly offsets the limited apparent maintainer redundancy.
There were no commits and no active maintainers during the last 3 months. The repository was pushed on the release date and the registry shows regular releases, which softens but does not remove the concern about ongoing source maintenance.
The repository name does not match the package name and its README does not mention the package. That raises a concrete concern that the linked source may not actually correspond to this release.
Composer build tooling is present, but no security-scanning tooling was detected. This is a transparency and maintenance gap rather than evidence of a defect.
The repository has no security policy. That leaves vulnerability-reporting and response expectations undocumented for a package that provides filesystem, network, and encryption helpers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
thecodingmachine/safe Version >=1.3 <2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.