The package is licensed, documented, tested, and has a release for this version. Workflow references are unpinned and no security policy or scanning is present, while organization backing reduces the impact of its concentrated contributor base.
68%
Total Score
67
100
88
67
The package has six releases over about 22 months, but only one release in the last 12 months; this suggests a modest and slowing release cadence rather than abandonment.
All recent commits come from one contributor, creating concentration risk; organization ownership provides some capacity to hand maintenance off, so this is a caution rather than a severe risk.
Only one commit was recorded in the last three months from one active maintainer, indicating limited recent maintenance activity.
Composer build tooling is present, but no security-scanning tooling was detected, leaving an avoidable project hygiene gap.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rapidez/core Version ^4.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.