This release appears healthy and suitable for dependency use: it has a long release history with frequent recent releases, a stable non-prerelease version, no registry deprecation, an active and non-archived repository, reproducible-looking Composer scaffolding, repository tests and CI workflows, and a balanced two-person recent contributor base. The main reservations are the absence of a repository security policy and explicit GitHub Actions token permissions, plus no configured security-scanning tool; these are security-hygiene gaps rather than evidence of abandonment. The package artifact omits tests and a changelog, but repository tests and CI materially compensate for those omissions.
86%
Total Score
90
100
94
80
The repository is owned by a named user rather than an organization, so the project has individual-owner backing. Recent activity from two contributors partially offsets the resulting continuity risk.
Composer build tooling and repository quality configurations are present, but no security-scanning tool was detected. The missing security automation is a genuine hygiene gap, though it does not by itself indicate unsafe maintenance.
The repository has no security policy. This weakens vulnerability-reporting transparency and response expectations, although it is not evidence that the package is abandoned.
All three workflows lack top-level token permission declarations. Even though none declares top-level write access, explicitly limiting permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.