55%
Total Score
caution
Usable with caveats: no releases or repository commits have appeared since November 2024.
The package has had only 4 releases, with none in the last 12 months; its latest release was on November 11, 2024, roughly 22 months ago. This is a substantial maintenance concern despite the package not being deprecated.
The package runs a post-install command, so installation performs additional actions beyond extracting dependencies. This is an operational and review concern for a package that also installs application functionality.
The package and repository are owned by the same individual account, providing direct ownership alignment but no organization-level backing. This leaves a relatively thin support structure.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap. That weakens evidence of ongoing maintenance.
The repository uses Composer build tooling, but no security scanning tools were detected. That is a modest transparency gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.2 | — | — |
symfony/console Version ^5.4 | — | — |
peppeocchi/php-cron-scheduler Version ^4.0 | — | — |
vgrish/core-vendor-autoload-modx2 Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.