A small organization-backed project has tests, release notes, and a security policy. Its registry releases stopped over two years ago and recent repository activity is absent, so pinning this version carries maintenance risk.
55%
Total Score
75
90
75
The package runs post-install and post-update Composer scripts, which add installation complexity and execution surface. These are not severe on their own, but they modestly reduce transparency for consumers.
The package has 580 releases but none in the last 12 months; the latest release was over two years ago. That indicates a meaningful maintenance concern despite its historically active release count.
The repository recorded zero commits and zero active maintainers during the last three months. This reinforces the risk suggested by the lack of recent registry releases.
The only workflow was fully analyzed with no dangerous audit findings, but both of its two action references are unpinned. That is a supply-chain hygiene gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version 1.1.4 | — | — |
mustache/mustache Version ^v2.14.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.