The Apache-2.0 licensing, included tests, and organization ownership provide useful baseline transparency. Treat it as an early dependency and watch for a second release before standardizing on it.
68%
Total Score
75
100
86
83
The package was released today and has only one release, so there is no established release cadence or track record yet. Its organization-backed repository provides some context, but not evidence of sustained maintenance.
There were no commits or active maintainers in the past three months, but the repository was created and pushed today, making that absence expected rather than evidence of a long-term collapse.
Composer build tooling is present, but no security scanning tools were detected. This is a modest hygiene gap, not evidence that the package is unsafe.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear. This is a documentation gap rather than a direct maintenance failure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
filament/infolists Version 5.8.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.