57%
Total Score
caution
Usable with caveats: no releases in the last 12 months and little visible project activity.
The repository is owned by an individual user rather than an organization. That is not inherently unhealthy, but it offers less visible institutional backing for a package whose recent activity has paused.
The package has 119 releases since April 2023, but none in the last 12 months and its latest release was in December 2024. That long pause lowers confidence in ongoing maintenance.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is consistent with a quiet project and provides no evidence of active community maintenance.
The repository has zero stars and forks and only one watcher. Popularity is not required for a healthy package, but these counters provide little supporting evidence of community adoption.
Composer is used for builds, but no security-scanning tooling was detected. That is a transparency and hygiene gap, though it is not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
stancl/tenancy Version ^3.7 | — | — |
bluedot/composer Version 3.6.4 | — | — |
hubspot/api-client Version ^8.4.1 | — | — |
alibabacloud/devops-20210625 Version 2.1.6 | — | — |
alibabacloud/dysmsapi-20170525 Version 2.0.23 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.