Its MIT license, README, tests, and stable release history provide useful transparency. The project has no security policy or scanning, and its broad runtime dependency set adds maintenance overhead.
67%
Total Score
50
50
94
75
Seventeen runtime dependencies create a relatively broad dependency surface for a workflow engine, increasing the amount of upstream maintenance and compatibility risk to track.
Only one registry account, Bingo-Soft, has publish access. This is a modest concern, though registry access alone does not establish the project's actual maintenance capacity.
The repository is owned by a personal GitHub account rather than an organization, so the concentrated recent activity has no demonstrated organizational handoff shown by the provided evidence.
One contributor made all recent commits, leaving maintenance dependent on a single active developer and increasing continuity risk.
Only two commits were recorded in the last three months, indicating limited recent development activity despite recent releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.2 | — | — |
bingo-soft/el Version * | — | — |
phpixie/image Version ^3.3 | — | — |
bingo-soft/sax Version * | — | — |
bingo-soft/xml Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.