The package includes tests, release notes, and a matching Apache-2.0 license. It is backed by an organization, uses no install-time scripts, and has a clear Composer source tree.
60%
Total Score
50
75
75
The repository recorded zero commits and zero active maintainers in the last three months. This is the strongest maintenance concern and raises the chance that fixes may be slow.
The package has 11 releases since December 2020, but no releases in the last 12 months despite the latest release being in September 2025. This indicates a recent slowdown rather than clear abandonment.
There are four open issues, with no new or closed issues and no pull requests merged in the last month. This suggests limited current project activity, though the backlog is small.
The repository name does not match the package name and its README does not mention the package. Because both checks fail, the repository's relationship to this release is less transparent.
Composer is used as a build tool, but no security scanning tooling was detected. The missing scanning is a hygiene gap, partially offset by the package's small, test-covered source tree.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.