Tests, a README, and a matching MIT license provide a solid starting point. The young project has limited operational transparency, with no security policy or scanning and a repository that does not clearly identify the package.
58%
Total Score
50
100
71
75
Three releases over 340 days, with all three in the last 12 months and a median interval of about 94 days, show an emerging but not yet mature release history.
The repository recorded zero commits and zero active maintainers in the last three months, leaving current maintenance capacity unproven.
There are 10 open pull requests, with one new pull request but no merged pull requests in the last month; this suggests pending work without clear evidence of follow-through.
The repository name does not match the package name and its README does not mention the package, so the repository may not clearly belong to this release.
The project uses Make and Composer, but no security scanning tools were detected, leaving a security-maintenance gap for a dependency library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shrikeh/cqrs Version ^0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.