The Apache-2.0 license, organization ownership, and included tests provide a solid baseline. Its tiny dependency profile is appropriate for an implementation package, but there is not yet enough history to establish dependable maintenance.
55%
Total Score
75
100
83
75
The package was released only once and is zero days old, so there is no release track record from which to judge maintenance or stability.
No commits and no active maintainers were recorded during the last three months. Because the repository is newly created, this mainly means maintenance capacity is unproven rather than demonstrating long-term abandonment.
The repository has zero stars, forks, and watchers. For a package released today, this is weak supporting evidence rather than a standalone health failure.
Composer is used as a build tool, providing normal package tooling, but no security scanning tool was detected. The missing scanning is a modest transparency and hygiene gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a hygiene concern, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
dragonmantank/cron-expression Version 3.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.