MIT licensing, repository tests, and a matching organization-backed source make the package transparent and maintainable. Its small dependency set and clean workflow audit reduce adoption friction, but recent activity is limited.
65%
Total Score
75
100
88
75
The package has existed for about 6 years, with 15 releases and one release in the last 12 months. That supports maturity but indicates a slower recent release cadence.
There were zero commits and zero active maintainers in the last three months. The recent repository push and release provide some counter-evidence, but the current maintenance gap still lowers confidence.
Composer is used as the build tool, but no security scanning tooling was detected. The missing scanning is a modest transparency and maintenance gap.
The repository has no security policy. For a maintained library this weakens vulnerability-reporting transparency, although it is not evidence of an active security problem.
The only workflow was fully analyzed with no audit findings and no untrusted checkout or script-injection sinks. Its single action reference is unpinned, which is a minor reproducibility and supply-chain hygiene gap; the pull_request_target trigger is not dangerous on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.19 | — | — |
aeon-php/calendar Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.