The package is compact, licensed, and documented, with release notes and tests covering the latest nullable-value changes. It has no security scanning or security policy, which limits transparency for a small individually maintained project.
67%
Total Score
50
100
89
83
Only one account has registry publish access. The repository is owned by an individual rather than an organization, so the narrow publishing base provides limited continuity if that maintainer stops work.
The registry namespace and repository are owned by the same individual account, so there is no organizational backing shown to compensate for the single-maintainer structure.
The repository recorded zero commits and zero active maintainers during the last three months. That is a meaningful maintenance concern, even though a recent release shows the project has not been abandoned outright.
The repository has one star, one fork, and no watchers. Low adoption is not a health verdict, but it provides little external evidence of broad review or community support.
Composer build tooling is present, but no security-scanning tools were detected. For a small package this is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
vsilva472/phpcpf Version ^1.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.