The MIT license, consumer README, source tests, and release notes provide useful transparency. Maintenance is currently quiet, and the registry marks this package abandoned, so pinning it creates avoidable migration risk.
45%
Total Score
88
100
81
75
Packagist marks the entire package as abandoned and identifies dragon-code/support as the replacement. This is a major adoption and continuity concern even though the source repository remains available.
The project has a long history with 188 releases, but only 2 releases in the last 12 months, indicating substantially slower recent activity.
There were no commits and no active maintainers in the last 3 months, which weakens the evidence of ongoing maintenance despite the recent repository push and release history.
No repository security policy is present. This is a transparency gap, although the package is a general helper library and other tooling provides limited compensation.
All five workflows were analyzed with no audit findings or untrusted-trigger sinks, but all 9 action references are unpinned and two workflows grant top-level write permissions. This is a workflow hygiene concern, not a severe dependency-health risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0.1 || ^2.0 | — | — |
voku/portable-ascii Version ^1.4.8 || ^2.0.1 | — | — |
dragon-code/contracts Version ^2.22.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.