It has an MIT license, tests, a readable README, and no install-time scripts. The workflows also include a high-confidence unpinned container image, adding release hygiene risk.
32%
Total Score
0
100
57
100
The latest registry release was over four years ago, with no releases in the preceding 12 months. That strongly suggests abandonment despite the package having 187 historical releases.
The repository had zero commits and zero active maintainers in the three months measured. Combined with the old last push, this is strong evidence that maintenance has stopped.
The linked repository name does not match the package name and its README does not mention the package. That makes the repository-to-package relationship unclear and weakens source transparency.
The repository uses Composer build tooling, showing a defined build process. No security scanning tools were detected, which is a minor hygiene gap rather than a primary health concern.
The repository is not archived, which is a compensating sign, but it was last pushed nearly five years ago. The absence of an archive marker does not offset the stale source activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.