The package includes release notes, a repository license, and a security policy. Maintenance has slowed, with no releases in over two years and no commits in the last three months; all three workflow actions are unpinned.
65%
Total Score
67
100
83
83
The artifact and repository both contain a license, but the artifact declares GPL-2.0-or-later while the detected license is GPL-2.0. The release is licensed, though the narrower detected text does not fully confirm the broader declaration.
The package has 16 releases since May 2017, but none in the last 12 months; the latest release was over two years ago. This indicates slowing maintenance, although the long project history provides some maturity.
There were no commits and no active maintainers in the last three months. This is a meaningful maintenance concern, although the repository was pushed in November 2025 and is not archived.
Only two issues are open, with no new issues or pull requests in the last month. The low volume is not itself harmful, but it provides little evidence of active ongoing maintenance.
The repository uses Composer build tooling, but no security scanning tools were detected. The build setup is present; the missing scanning is a modest hygiene gap rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.