The README explains the metapackage's purpose and Composer dependency clearly, and organization backing adds accountability. Its maintenance record is too short to establish maturity, with no security policy or scanning evidence yet.
70%
Total Score
75
100
83
50
This is the package's first release, published today, so there is not yet enough history to demonstrate sustained maintenance; its very recent creation limits the abandonment concern.
No commits or active maintainers were observed in the past three months, but the repository was pushed today and the package has only just been released, so this is mainly an unproven-maintenance concern rather than evidence of abandonment.
The repository uses Composer, but no security-scanning tool was detected. For a tiny type-definition metapackage this is a modest transparency gap, not a severe supply-chain concern.
No security policy was found. That leaves vulnerability-reporting expectations unclear, though the package is a small metapackage with no install-time lifecycle scripts.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/filp-whoops-impl Version ~2.18.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.