The package includes its license, README, and changelog, with no install-time scripts or excessive runtime dependencies. The single recent commit and absent security policy leave maintenance and security processes thin despite organization backing and an unarchived repository.
57%
Total Score
67
100
79
75
There has been only one registry release, nearly five years ago, with no releases in the last 12 months. Recent repository activity partly offsets the age of the published release but does not establish a reliable release cadence.
All one recent commit came from a single contributor, creating a concentrated operational dependency. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository has only one commit in the last three months, showing some current activity but a very sparse maintenance pace. That weakens confidence that fixes and releases will arrive consistently.
Composer build tooling is present, but no security scanning tooling was detected. This is a process gap rather than evidence of an unsafe release.
The repository has no security policy, so there is no documented reporting or response process for vulnerabilities. The gap affects transparency but is not a severe risk by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.