The package is intentionally minimal and clearly documents how it should be consumed. Its Apache-2.0 licensing and matching repository help, but there is not yet a maintenance track record or security policy.
76%
Total Score
83
100
89
88
This is the first release and the package is only 0 days old, so there is no release or maintenance history yet. The newly created, active repository partly supports the launch but cannot establish long-term reliability.
There were 0 commits and 0 active maintainers in the last 3 months because the repository is newly published. This leaves maintenance capacity unproven rather than demonstrating a collapsed project.
The repository uses Composer, matching the package ecosystem, but no security scanning tool was detected. For this tiny metapackage that is a modest hygiene gap.
No security policy was found in the repository. This reduces disclosure transparency, although the package contains minimal scaffolding rather than substantial runtime code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/webmozart-assert-impl Version ~2.4.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.