The organization-backed project has clear licensing, a useful README, and a clean workflow audit. It lacks a security policy or scanning tools, which leaves maintenance and security practices less transparent.
60%
Total Score
75
80
50
The package has 50 releases over roughly two years, but only one in the last 12 months despite a historical median interval of about 3 days, indicating a major slowdown.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with a currently inactive development process.
Composer is used for the build, but no security scanning tools are configured; this is a modest transparency and maintenance gap.
No security policy is present, so vulnerability reporting and response expectations are not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
salient/utils Version self.version | — | — |
salient/container Version self.version | — | — |
salient/contracts Version self.version | — | — |
salient/iterators Version self.version | — | — |
psr/event-dispatcher Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.