The metapackage has a clear README, matching repository, and only one runtime companion. At one day old, it has no demonstrated release or commit track record, so confidence in long-term maintenance is limited.
68%
Total Score
75
100
88
88
This is the first and only release, published less than one day ago, so there is no release history demonstrating sustained maintenance. The signal reflects limited maturity rather than abandonment.
No commits or active maintainers were recorded in the last three months. Because the repository itself is less than one day old, this shows no demonstrated track record rather than a clear collapse in activity.
The repository uses Composer, matching the package ecosystem, but no security scanning tool was detected. For this small metapackage this is a minor transparency gap, not a severe risk.
No repository security policy was found. This modestly reduces disclosure transparency, although the package is a narrow metapackage with no install-time scripts.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/vlucas-phpdotenv-impl Version ~5.7.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.