Usable with caveats: the package is licensed, linked to an active organization-owned repository, and has a stable release with no deprecation or install scripts. However, the repository had no commits or active maintainers in the last three months, and its CI lacks explicit token permissions and security scanning.
68%
Total Score
83
100
83
88
The package is about 371 days old with three releases, including two in the last 12 months and a median interval of about 23 days; this shows some release activity but limited maturity.
There were zero commits and zero active maintainers in the last three months, a concrete sign that maintenance may have slowed or paused.
The repository has two stars and no forks, indicating a small user base; this is supporting context rather than a health verdict, and the organization backing partly offsets it.
The repository uses Composer build tooling but reports no security-scanning tools, leaving an avoidable gap in ongoing project hygiene.
The sole workflow has no top-level token permissions declaration, so its GitHub Actions privileges are not explicitly minimized.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.