The MIT license, complete README, and release notes make the package straightforward to evaluate and integrate. Maintenance capacity is limited by no commits in the past three months and one registry publisher, though organization backing and a recent release reduce abandonment concerns.
70%
Total Score
67
100
93
75
Only one account has registry publishing access, which limits visible publishing redundancy. This is partly offset by the repository being owned by an organization, so it is a moderate rather than severe concern.
The repository recorded zero commits and zero active maintainers in the past three months. A release was still published recently, but the lack of ongoing commit activity is a meaningful maintenance warning.
Composer is used for builds, but no security-scanning tooling was detected. This is a hygiene gap rather than evidence that the package is unsafe, especially given the recent release activity.
No security policy was found in the repository, leaving vulnerability reporting expectations unclear. This lowers transparency but is not, by itself, evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
blitz-php/utilities Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.