Repository tests, a security policy, readme, and strong workflow controls provide useful transparency. The single maintainer and zero observed commit activity leave little evidence of sustained maintenance beyond the initial release burst.
65%
Total Score
50
100
94
100
Only one registry account has publishing access. That is workable for a small individual project but provides limited publishing redundancy.
Four releases were published within the same day, showing an initial release burst but no meaningful history for judging long-term maintenance.
No commits or active maintainers were observed over the last three months. Because the project is newly published, this mainly means sustained maintenance is unproven rather than established abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 || ^2.0 | — | — |
wobqqq/fortify-plugin Version ^1.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.