The project has solid tests, documentation, MIT licensing, and a small dependency surface. Its single-maintainer profile and absent security policy leave less resilience if maintenance stops.
68%
Total Score
50
100
89
83
The package has existed since 2013 but has made no release in about two years and five months; the long median interval also indicates slow maintenance.
There were no commits and no active maintainers during the last three months, reinforcing the evidence of a stalled maintenance cycle.
The repository uses Composer and Make for builds, but no security-scanning tooling is configured, leaving a modest hygiene gap.
The repository has no security policy, so it gives maintainers and users no documented process for reporting vulnerabilities.
Both workflows were analyzed without dangerous triggers or audit findings, but all 8 action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.