Licensing and package identity are clear, and the README gives usable setup instructions. The small project footprint and install hook leave limited safety margin for a dependency that has not been refreshed.
40%
Total Score
0
75
50
The latest release was 22 October 2019, with no releases in the last 12 months; nearly seven years without a release strongly suggests abandonment risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and weak evidence of ongoing maintenance.
A post-autoload-dump install hook runs package code during dependency installation, adding execution surface that deserves attention even though the signal does not establish malicious behavior.
The repository has zero stars and forks and only one watcher, providing little supporting evidence of an active user or contributor community.
Composer build tooling is present, but no security-scanning tools were detected, reducing automated oversight alongside the inactive project history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
skinnybot/basic Version ~2.0 | — | — |
skinnybot/module Version ~2.0 | — | — |
skinnybot/skinny Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.