Its single runtime dependency keeps the package small, and the release includes clear usage documentation, a changelog, and licensing. The repository is identifiable and active enough to avoid abandonment signals, but the published release history remains very thin.
58%
Total Score
50
100
88
83
The repository is owned by an individual account rather than an organization, so there is no visible organizational backing to compensate for the thin release history.
The package has only one release, published about six years ago, with no releases in the last 12 months. A repository push in January 2025 provides some compensating evidence, but the registry release history still indicates limited maintenance.
There were no commits and no active maintainers in the last three months. The January 2025 push partly offsets this, but recent activity is still absent.
The repository uses Composer, but no security scanning tooling was detected. This is a modest transparency and maintenance gap, not evidence that the package is unsafe by itself.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
northox/stupid-password Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.