The repository is small but includes tests and GitHub release tooling, and the package declares a GPL license. Security scanning is absent, while no recent registry releases and no commits in three months limit confidence in ongoing support.
58%
Total Score
50
100
88
83
Only one registry maintainer is listed, leaving a thin publishing base and increasing continuity risk for a small project.
The repository is owned by an individual rather than an organization, so the single-maintainer concern is not offset by visible organizational backing.
The package has only two releases, both in August 2024, with no releases in the last 12 months despite being about two years old. This is a meaningful maintenance concern.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the lack of recent releases, this weakens evidence of active maintenance.
Composer is used for builds, but no security-scanning tools are present. The missing scanning is a hygiene gap rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^v9.5.31 || ^v10.4.37 | — | — |
cyber-duck/pardot-api Version ^3.0.0 || dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.