The MIT license, small runtime dependency set, repository tests, and release notes support adoption. Recent repository work is limited to one contributor, and the GitHub Actions references are all unpinned; there is also no security policy.
68%
Total Score
67
100
86
50
The package has 31 releases over roughly nine years, but its latest release was about 18 months ago and there were no releases in the last 12 months. Recent repository activity partly offsets this, but the release cadence is a real maintenance concern.
One contributor made all four commits in the last three months, creating a concentrated maintenance dependency. Organization backing provides some handoff capacity, but no second active contributor is shown.
The repository had four commits in the last three months, showing current maintenance, but all activity came from one active maintainer.
Composer build tooling is present, but no security-scanning tooling was detected, leaving automated security coverage unclear.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.