The MIT license file conflicts with the proprietary manifest, and the repository offers no README or security policy for users to assess. The organization-backed repository matches the package, but its maintenance record is very thin.
42%
Total Score
75
71
75
The artifact contains an MIT license file, but the manifest declares the package proprietary. The conflicting declarations create avoidable uncertainty for downstream users despite the presence of a license.
The package has no README, while this library exposes many classes and integrations that consumers need to understand. Missing tests and changelog files are normal packaging practice and do not add concern here.
This is the only release, published nearly three years ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance or compatibility work.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long period since the only release. Organization backing does not compensate for absent recent development activity.
Composer is used for the build, but no security scanning tool is configured. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
quantaforge/support Version ^1.0.0 | — | — |
quantaforge/contracts Version ^1.0.0 | — | — |
quantaforge/macroable Version ^1.0.0 | — | — |
quantaforge/collections Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.