This is a generally healthy and usable release: it has a six-year release history with 39 releases, eight releases in the last 12 months, a stable non-prerelease version, no registry deprecation, a linked non-archived repository, and clear licensing. The repository and artifact are well structured, include documentation, changelog and security policy files, and the artifact has no install-time lifecycle scripts. The main concerns are that recent repository activity is limited to two commits over three months from one contributor, the package has only one registry maintainer, and no security scanning tooling was detected. Repository tests compensate for the absence of packaged tests, but the narrow maintenance base warrants some dependency-review caution.
78%
Total Score
60
100
94
100
Only one account has registry publish access. That is a genuine continuity concern for a user-owned project, although repository release history and recent activity show that the maintainer is currently active.
The repository is owned by an individual user rather than an organization. This does not make the package unsafe, but it means the single-maintainer and bus-factor concerns are not offset by visible organizational backing.
One contributor made all two commits in the last three months, producing a 100% top-contributor share. With a user-owned repository and no organizational backing, this creates a meaningful single-maintainer continuity risk.
Only two commits were recorded in the last three months, indicating a low maintenance cadence. Recent releases partially compensate for this, but the repository activity itself is limited.
The repository uses build tooling through Just and Composer, but no security scanning tools were detected. The build tooling is positive, while the missing security automation is a hygiene gap rather than a severe health risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version ^3.4 | — | — |
symfony/process Version ^7.4|^8.0 | — | — |
rockett/pipeline Version ^4.1 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.