Clear licensing, documentation, tests, and a recent repository push support adoption. The lack of a security policy leaves less transparency around vulnerability handling.
67%
Total Score
50
100
88
88
The repository is owned by an individual rather than an organization, so the concentrated maintainer and contributor activity is not offset by visible organizational backing.
The package has only two releases over 627 days, with one release in the last 12 months and a median interval of about 563 days; this indicates a slow maintenance cadence.
All recent commits come from one contributor, leaving maintenance dependent on a single active person and increasing continuity risk.
Only one commit was recorded in the last three months, with one active maintainer; this is evidence of limited recent maintenance capacity despite the recent push.
Composer build tooling is present, but no security scanning tooling was detected, leaving automated security coverage limited.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.