The package has tests, release notes, no runtime dependencies, and a source repository that matches the package. Single-person ownership and missing security tooling leave limited backup if maintenance is needed.
57%
Total Score
50
100
86
75
One registry maintainer is a small support base, and the linked repository is owned by a user rather than an organization. This is not an abandonment verdict by itself, but it leaves limited visible backup.
The latest release was about 2 years and 2 months ago, with no releases in the last 12 months. The earlier seven-release history shows initial activity but does not offset the current pause.
The repository had no commits or active maintainers in the last 3 months, reinforcing that development is currently inactive.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap for a package with no other major supply-chain indicators.
The repository has no security policy, reducing clarity about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.