Tests, documentation, and a clear license support routine adoption. The inactive repository and unpinned workflow actions leave maintenance and build-integrity concerns for long-term use.
62%
Total Score
75
100
88
83
The package is maintained under a personal registry and repository account rather than organization backing, so its single-person ownership offers limited continuity if the maintainer stops work.
The package has eight releases over roughly six years, but none in the last two years; this indicates a mature but currently inactive release cadence.
There were no commits and no active maintainers in the last three months, which is meaningful evidence of current inactivity despite the repository remaining available.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency gap rather than a severe risk.
The repository has no security policy, leaving no documented process for reporting vulnerabilities or coordinating fixes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0|^3.0 | — | — |
guzzlehttp/guzzle Version ^6.2|^7.1 | — | — |
guzzlehttp/promises Version ^1.5|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.