The package includes tests, a readable README, and no install-time scripts. Organization backing and a repository push in 2025 provide some support, but public maintenance is quiet, the linked repository does not identify this package, and no security policy is published.
52%
Total Score
75
100
81
75
The package has 12 releases since October 2018, but none in the last 12 months and its latest release was in July 2023. This materially weakens confidence in current maintenance.
There were zero commits and zero active maintainers in the last three months. This is a direct sign of currently quiet maintenance, even though the repository was pushed in February 2025.
The linked repository name does not match the package name and its README does not mention the package. That raises a concrete concern that the repository may not actually document or build this package.
The repository has no stars or forks and only one watcher, so it has little visible adoption evidence. Popularity is supporting evidence, however, and does not outweigh the maintenance signals by itself.
The repository has no security policy. That is a transparency and reporting gap, although it is less severe than evidence of unsafe workflows or a deprecated release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolyth/lodger Version ^1.1 | — | — |
vlucas/phpdotenv Version ^5.5 | — | — |
codger/javascript Version ^0.2.0 | — | — |
sensimedia/codger-sass Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.