The organization-backed repository and matching package source provide useful ownership evidence. However, the declared proprietary license conflicts with the detected MIT license, and the workflow uses an unpinned action without security scanning.
43%
Total Score
50
33
This is the package's only release, published nearly three years ago, with no releases in the last 12 months; that strongly raises abandonment risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and weakens confidence in ongoing maintenance.
The artifact contains an MIT license file, but the manifest declares the package proprietary. The conflicting declarations create avoidable licensing uncertainty despite the detected license file.
The project uses Composer, but no security-scanning tooling was detected. This is a modest transparency gap, while the organization-backed repository provides some compensating project context.
The sole workflow uses one unpinned action, while the pull_request_target trigger has no untrusted checkout or script-injection sink and no other audit findings. This is a limited reproducibility and workflow-hygiene concern, not a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
quantaforge/support Version ^1.0.0 | — | — |
quantaforge/contracts Version ^1.0.0 | — | — |
quantaforge/macroable Version ^1.0.0 | — | — |
quantaforge/filesystem Version ^1.0.0 | — | — |
quantaforge/collections Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.