The package is clearly organized, MIT-licensed, and has a useful README. Its organization-owned repository provides some continuity, while the install hook adds modest integration complexity.
61%
Total Score
67
100
83
67
The repository recorded zero commits and zero active maintainers in the last three months, with its last push about eight months ago. This is concrete evidence of stalled maintenance.
The package runs a post-autoload-dump install-time script. This is a modest transparency and installation-risk concern because code executes during dependency setup.
The package published 13 releases in a brief four-day period, then had no newer release for about eight months. That concentrated early activity does not demonstrate ongoing maintenance.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no external adoption signal to offset the quiet maintenance record.
The repository uses Composer build tooling, showing basic project packaging support, but it has no security-scanning tools. The missing scanning is a modest hygiene gap rather than a health verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
red-jasmine/captcha Version ^1.0 | — | — |
red-jasmine/support Version ^1.0 | — | — |
red-jasmine/jwt-auth Version ^1.0 | — | — |
red-jasmine/socialite Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.