The repository has no security policy or security scanning, so maintenance safeguards are limited. Tests, licensing, and an organization-owned repository provide useful supporting evidence, but the project is still very immature.
58%
Total Score
83
100
81
88
The package is effectively new: its first release was only about 2 minutes before collection, with just 2 releases and a median interval of about 26 seconds. That provides little evidence of established maintenance or release reliability.
There were 0 commits and 0 active maintainers in the last 3 months. Because the repository is only minutes old, this is consistent with a newly created project but still leaves maintenance capacity unproven.
The repository has 0 stars, forks, and watchers. This is weak supporting evidence, but the package's age makes low popularity expected and it is not decisive on its own.
Composer is used as the build tool, which fits the package, but no security scanning tools are configured. That weakens ongoing supply-chain hygiene.
The repository has no security policy. For a package intended to be consumed as a dependency, this reduces transparency about vulnerability reporting and handling.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version 12.5.35 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.