Healthy and suitable to use, with a strong release history, recent maintenance, clear licensing, and good package structure. The main caveat is that all recent repository commits come from one contributor, while the project has very little public adoption and no security policy.
82%
Total Score
75
100
89
90
One contributor made all 18 commits in the last 3 months, creating a concentrated maintenance risk. Organization backing provides some handoff capacity, but no second active contributor is shown.
There are no open issues or pull requests, and no recent issue or pull-request activity. This is consistent with a quiet project, but provides little evidence of a broader support community.
The repository has only 1 star, 0 forks, and 1 watcher, so there is little public adoption or external validation; this is a concern but not decisive against a package with active releases.
Composer is used for builds, but no security-scanning tool is configured. The build tooling is appropriate, while the missing scanner is a modest transparency gap.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.