The repository has tests, documentation, and steady recent commits. The registry record is brand new, while the package identity and license do not line up and workflow references are unpinned; verify provenance before adopting.
55%
Total Score
100
100
69
50
The artifact and repository contain license files, but the manifest declares GPL-3.0-or-later while the detected license is Apache-2.0. That mismatch creates a real legal and transparency concern despite the presence of licensing.
This is the package's first and only registry release, published today, so there is no release history to establish maturity or stability. Active repository commits partly offset the lack of registry history.
The linked repository name does not match the package name and its README does not mention the package. That makes package-to-source identity harder to verify and raises provenance concern.
Composer build tooling is present, but no security scanning tool was detected. The missing scanning is a modest hygiene gap rather than evidence of abandonment.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a framework intended for application development.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
zubzet/password-hash-utilities Version 1.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.