The repository includes tests, a clear README, and matching organization-backed source, while licensing is explicit. Its single release and zero recent commits leave maintenance longevity unproven, and no security scanning is configured.
62%
Total Score
75
86
75
This is the package's first and only release, published today, so there is no release history to demonstrate sustained maintenance. Its very recent publication explains the lack of history but does not remove the uncertainty.
The repository has no commits or active maintainers in the past three months. Because the repository was also created today, this is more a lack of maintenance evidence than proof of abandonment, but longevity remains unproven.
Composer is used as the build tool, which fits the package, but no security scanning tool is configured. That leaves a meaningful repository-hygiene gap for a package intended to be consumed as a dependency.
No security policy is present in the linked repository, reducing transparency around vulnerability reporting and response. This is a moderate hygiene concern rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
surface/fonts Version ^0.8.0 | — | — |
surface/contracts Version ^0.8.0 | — | — |
venusian-voyager/nuts-and-bolts Version ^0.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.