The matching repository, clear README, and Apache-2.0 licensing improve transparency. Its Composer-only metapackage design makes the minimal artifact reasonable; pin this exact version until the project demonstrates continued maintenance.
62%
Total Score
75
100
83
88
The package is only 0 days old with one release, so there is no release track record yet. This is a meaningful maturity gap, though it is consistent with a newly published package.
There were zero commits and zero active maintainers in the prior 3 months, but the repository and package were created only 0 days ago. This limits evidence of sustained maintenance rather than proving abandonment.
The repository has zero stars, forks, and watchers, but it is newly created and popularity is only supporting evidence. The counts therefore provide little maturity evidence without independently indicating abandonment.
The repository uses Composer as its build tool, which fits the package ecosystem, but no security scanning tooling is present. For this tiny metadata-oriented package, that is a minor hygiene gap.
The repository has no security policy. This reduces disclosure transparency, although the package is a small type-definition metapackage with no observed lifecycle scripts.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/composer-composer-impl Version ~2.10.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.