The project is small and clearly documented, with a current stable release and release notes. Its single-maintainer base and lack of security policy add some maintenance risk for a tool that changes PHP configuration.
63%
Total Score
50
100
94
50
A post-autoload-dump install script runs during Composer installation, so installation has behavior beyond merely downloading the package and merits some caution.
Only one registry maintainer is listed, leaving little visible publishing redundancy; the matching source repository shows this is an individual-owned project rather than organization-backed publishing.
The registry namespace and repository owner match, which supports consistent ownership; the owner is an individual account, so there is no organization backing to offset the thin maintainer base.
No commits and no active maintainers were recorded in the last three months, which weakens evidence of active maintenance despite the recent release.
Composer is used as the build tool, but no security-scanning tool is configured, leaving a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.