Recent releases show active maintenance, while only one commit and one active contributor appeared in the last three months. The organization-backed project and clear package documentation reduce the impact of that concentration; no security policy is a minor transparency gap.
78%
Total Score
67
93
75
All recent commits came from one contributor. The repository is organization-owned, which provides some handoff capacity, but no second active contributor is shown in this period.
Only 1 commit from 1 active maintainer was recorded in the last three months. That is limited recent activity, although the recent release and push show the project is not dormant.
Composer is used for builds, but no security scanning tool was detected. For a small library this is a modest transparency gap, not evidence of unsafe code.
The repository has no security policy. That weakens vulnerability-reporting transparency, though it is a minor concern for this small internal utility package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/collections Version ^2.2 || ^3.0 | — | — |
rekalogika/rekapager-contracts Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.