The package includes a README, tests, matching MIT licensing, and no install-time scripts. Its tiny, single-user project has limited operational and security maturity.
62%
Total Score
0
100
83
67
There were no commits and no active maintainers in the last three months, with the repository last pushed about eight months ago. This is a meaningful abandonment risk for a young package.
The repository has only 2 stars, no forks, and no watchers, providing little evidence of community review or shared maintenance capacity.
Composer is used for builds, but no security scanning tools are configured. This is a modest transparency and maintenance gap rather than a severe risk by itself.
The linked repository is not archived, although its last push was about eight months ago, so the non-archived status does not offset the maintenance concern.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
psr/event-dispatcher Version ^1.0 | — | — |
vaibhavpandeyvpz/databoss Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.