Organization backing, matching source, repository tests, release notes, and a security policy provide useful maintenance and transparency evidence. MIT licensing and no install scripts reduce adoption friction, while the small user base limits independent signals of maturity.
64%
Total Score
67
100
83
88
The package has existed for over 8 years but has only 8 releases, with one release in the last 12 months and a median interval of about 344 days. This indicates slow maintenance rather than abandonment because a recent release exists.
The repository recorded zero commits and zero active maintainers in the last 3 months. This is a meaningful maintenance concern, though it is partly offset by the recent release and recent repository push.
There is one open issue and two open pull requests, but none were created or merged in the last month. This suggests limited current community activity without proving abandonment.
The repository has 8 stars and 5 forks, indicating a small user and contributor footprint. Low popularity is supporting caution rather than a standalone health verdict.
The project uses Composer and Make for build tasks, but no security scanning tools were detected. The missing scanning layer is a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^3.1.8 | — | — |
elasticsearch/elasticsearch Version ^8.11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.