The repository remains active and the release is clearly licensed. Registry publishing has not kept pace, and no security policy or automated security scanning is present.
68%
Total Score
50
88
75
The package and repository are owned by the same individual account, which provides consistent ownership but not organization-level maintenance depth.
The package has 41 releases, but none in the last 12 months and the latest registry release was published in April 2022, making the consumed artifact stale.
The repository had no commits and no active maintainers in the three months measured, despite a more recent last-pushed timestamp; this leaves current maintenance cadence uncertain and does not offset the old registry release.
Composer is used for builds, but no security scanning tooling is configured, leaving automated detection of dependency or source issues weaker.
The repository has no published security policy, so there is no documented process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.