The repository includes a clear README, a matching source project, tests, and an explicit GPL-3.0 license. Its single-maintainer project has no security policy or scanning, which makes long-term support and oversight less certain.
62%
Total Score
50
100
81
83
The package and repository are owned by the same individual account. That is coherent ownership, but it also means the project has limited visible organizational backing.
The latest release was about 15 months ago, and there were no releases in the last 12 months. This materially raises the risk that compatibility and maintenance have stalled.
There were no commits and no active maintainers in the last 3 months, indicating weak recent maintenance activity.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest oversight gap.
The linked repository is not archived, although its last push was about 14 months ago and does not offset the lack of recent release activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.