The package is clearly licensed and has a focused four-file artifact with a useful README. Its organization backing and recent releases provide some continuity, though consumer-facing security documentation is limited.
72%
Total Score
67
100
94
88
One contributor made all two recent commits, leaving maintenance dependent on a single active person. Organization ownership provides some handoff capacity but does not remove the current concentration.
Only two commits were recorded in the last 3 months. This is recent activity, but the low volume limits evidence of sustained maintenance capacity.
Composer build tooling is present, but no security-scanning tools were detected. For a package that bundles or locates external command-line tools, this is a meaningful transparency gap.
The repository has no security policy. This does not show a security defect, but it gives users no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
restruct/dot-static Version ^2.0 | — | — |
restruct/xpdf-static Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.