The package includes tests, a changelog, and a clear MIT license. Organization backing and a repository push about two months ago help offset single-contributor activity, absent security scanning, and unpinned workflow actions.
72%
Total Score
67
100
88
75
All 3-month commit activity came from one contributor, giving the project a concentrated recent bus factor. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository recorded 1 commit in the last 3 months, showing recent activity but a fairly light maintenance pace.
Composer is used for builds, but no security-scanning tool is reported. The missing scanning is a modest transparency and maintenance gap, not evidence of unsafe code.
The repository has no published security policy. That weakens vulnerability-reporting transparency, although it does not by itself indicate abandonment.
v0.8.9 is not a prerelease, and no recent releases are prereleases. The package remains below a stable major version, which adds some compatibility uncertainty but is not an abandonment concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
atk14/files Version ^1.6 | — | — |
atk14/translate Version ^1.2 | — | — |
atk14/string-buffer Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.