The Apache-2.0 licensing is clear, the repository matches the package, and the organization backing adds useful ownership context. Its focused metapackage design and lack of install scripts reduce integration risk, but there is no security policy or scanning evidence yet.
65%
Total Score
75
100
86
75
The package is 0 days old with only 1 release, so there is not yet enough release history to demonstrate sustained maintenance or maturity.
There were 0 commits and 0 active maintainers in the last 3 months. Because the package was created today, this is mainly missing history rather than evidence of abandonment, but it limits confidence.
The repository uses Composer, but no security scanning tools were detected. That is a modest supply-chain hygiene gap for a newly published package.
No security policy was found in the repository, leaving the process for reporting and handling vulnerabilities undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/spatie-backtrace-impl Version ~1.8.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.