Clear documentation, tests, an MIT license, and a small runtime dependency keep adoption straightforward. The workflow uses four unpinned actions and the repository has no security scanning, so maintenance would need closer review.
58%
Total Score
25
100
83
83
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the January 2020 last push, this is strong evidence of inactive maintenance.
The registry namespace and repository owner match an individual account. This is consistent ownership context, but it does not provide organizational backing to offset the inactive repository.
The package has five releases since June 2012, but its latest release was in January 2020 and it had no releases in the following 12 months. This indicates substantial staleness for a dependency.
Composer is used for the build, but no security-scanning tools are present. This is a maintenance and transparency gap, though it is not severe enough to make the release unfit by itself.
The linked repository is not archived, although its last push was in January 2020. The non-archived status is mildly reassuring but does not offset the lack of recent activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.