This release appears usable and actively maintained: it is not deprecated or archived, has had 39 releases in the last 12 months with the latest published recently, and the linked repository contains a substantial source tree, documentation, and tests even though tests are not packaged. The main risks are project immaturity, complete dependence on one active contributor, no security policy, and no adoption indicators; these warrant caution but are partly offset by recent commit activity, build and security tooling, package-repository alignment, and a clear MIT license.
78%
Total Score
60
100
89
90
Only one account has registry publish access. This is a genuine continuity risk for a young package, although repository activity shows that the same owner is actively maintaining it.
The repository is owned by an individual user rather than an organization, so there is no organizational maintenance redundancy to offset the concentrated maintainer base.
One contributor made all 20 commits in the last 3 months, creating a low bus factor and meaningful abandonment-continuity risk for a user-owned project.
There are no open issues or pull requests and no recent issue or pull-request activity. This is neutral for a small package but provides little evidence of community engagement or external review.
The repository has zero stars, forks, and watchers. This provides no external adoption or redundancy evidence, but low popularity alone is not evidence that the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
andydefer/php-jsonl Version ^0.11.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.