Usable with caveats: it is a small, clearly backed package with tests, a matching repository, and a stable MIT release, but maintenance is unproven. It has only one release and no commits or active maintainers recorded in the last three months, with no security policy or explicit workflow permissions.
58%
Total Score
75
100
88
80
Only one release has been published, with the latest release about nine months ago. This gives little evidence of sustained release maintenance, although a small package may not need frequent updates.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the single-release history, this is the strongest evidence that ongoing maintenance has not yet been demonstrated.
Composer build tooling is present, but no security-scanning tool was detected. For a small PHP library this is a hygiene gap rather than evidence that the package is unfit to use.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it is a process gap rather than a direct indication of abandonment.
The sole workflow lacks top-level token permissions, so its intended access is not explicitly constrained. No workflow requests top-level write access, which limits the severity of this hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/console Version ^6.4 || ^7.4 | — | — |
symfony/event-dispatcher Version ^6.4 || ^7.4 | — | — |
aeatech/snapshot-profiler-contracts Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.