The project still has recent commits, tests, release notes, and organization backing. Its release cadence has stalled, while all workflow actions are unpinned and no security policy is published.
65%
Total Score
75
88
75
The package has 40 releases over roughly 10 years, but it had no releases in the last 12 months despite being an established dependency. That weakens confidence in ongoing release maintenance.
All 5 recent commits came from one contributor. Organization backing provides some handoff capacity, but no second active contributor is shown, leaving maintenance concentrated.
There are 8 open issues and 1 open pull request, with no issues or pull requests closed in the last month. This suggests limited recent issue throughput, though it is not evidence of abandonment by itself.
The project uses Composer build tooling, but no security scanning tools are reported. This is a modest transparency and maintenance gap rather than a severe risk.
No repository security policy is published, leaving vulnerability-reporting expectations unclear.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.