Tests, release notes, security tooling, and organizational backing provide useful support. The small project and limited recent activity leave less evidence of sustained maintenance than a stronger dependency would have.
68%
Total Score
67
100
93
75
The package has been published since 2018 with 22 releases, but only one release appeared in the last 12 months, which is modest evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign of currently sparse development activity despite the recent push timestamp.
There are four open issues but no new or closed issues and no merged pull requests in the last month, providing limited evidence of active project interaction.
The repository has no published security policy, leaving vulnerability-reporting expectations and response guidance less transparent.
Both workflows were analyzed successfully and contain no reported findings or untrusted checkouts, but all six action references are unpinned, weakening reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^2 | — | — |
woohoolabs/yang Version ^3.0 | — | — |
php-http/guzzle7-adapter Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.