The package has a clear BSD-3-Clause license, tests, release notes, and a small complete source tree. Its organization-backed repository and inactive issue tracker provide some context, but no security policy or scanning leaves less assurance for future maintenance.
55%
Total Score
50
100
78
83
The latest release was nearly seven years ago, with no releases in the last 12 months. Six releases over the package's lifetime show prior maintenance, but the long gap materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the nearly seven-year release gap and indicating no current maintenance activity.
There are no open issues or pull requests, which avoids an unresolved backlog but also provides no evidence of current community or maintainer activity.
The repository has zero stars and one fork, so there is little external adoption evidence. Popularity is supporting evidence only, and the complete package structure provides some compensation.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance-hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
starlit/db Version ~0.14 | — | — |
starlit/validation Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.