KitDash 2.1.0 appears generally suitable to depend on: it is a stable, non-deprecated package with recent release activity, a repository that is not archived, 44 commits in the last 3 months, comprehensive README and test coverage, and a small runtime dependency profile. The main concerns are that all recent repository activity comes from one contributor, the repository has no security scanning or security policy, and the project has minimal external adoption evidence and no changelog. These are meaningful transparency and continuity risks, but they are outweighed by the package's recent maintenance, explicit licensing, tests, and coherent repository structure.
78%
Total Score
63
100
89
90
The repository is owned by an individual user rather than an organization, so there is no organizational maintenance backing to compensate for contributor concentration.
Only one contributor made all 44 commits in the last 3 months, creating a clear continuity and abandonment risk if that maintainer becomes unavailable.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is neutral to mildly limiting evidence because it may reflect a small or unused project rather than successful issue resolution.
The repository has 0 stars and 0 forks, with 1 watcher. This is weak adoption evidence, though popularity is supporting evidence rather than a health verdict and does not outweigh the observed maintenance activity.
Composer is used as a build tool, but no security-scanning tool is configured. Build tooling supports reproducibility, while the missing security automation leaves a hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.