Tests, documentation, release notes, and an MIT license make the package reasonably transparent. Its organization backing and matching repository help, but install scripts and unpinned workflow actions add maintenance and supply-chain friction.
62%
Total Score
83
83
50
Composer post-install and post-update scripts run during dependency operations, increasing installation complexity and the amount of package behavior executed automatically.
The package has 14 releases since September 2021, but none in the last 12 months; the latest release was about 14 months ago. This is a meaningful sign of slowing maintenance, despite the established release history.
There were no commits and no active maintainers in the last 3 months. Although the repository was pushed for the latest release, the current inactivity adds abandonment risk.
The repository has no stars or forks and only 3 watchers. Popularity is supporting evidence rather than a verdict, but these low adoption signals provide little independent confidence.
The repository uses Composer build tooling, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1||^2.0||^3.0 | — | — |
guzzlehttp/psr7 Version ^2.6 | — | — |
webmozart/assert Version ^1.11 | — | — |
guzzlehttp/guzzle Version ^7.8.2 | — | — |
symfony/serializer Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.