Tests and release notes provide some maintenance evidence, and the dependency surface is small. The long release silence and unpinned CI actions make this an aging dependency with limited ongoing assurance.
58%
Total Score
0
100
75
67
The package has nine releases since 2014, but none in the last 12 months and the latest registry release was in December 2019. This long release gap is a meaningful abandonment concern.
There were no commits and no active maintainers during the last three months. Combined with the lack of recent releases, this points to weak ongoing maintenance.
Published artifacts include tests, and this exact version has GitHub release notes documenting a bug fix. The missing README reduces consumer transparency for a library, but the repository also contains tests.
Composer build tooling is present, but no security scanning tools were detected. This is a modest assurance gap rather than evidence that the package is unfit.
The repository has no published security policy, leaving vulnerability reporting and handling expectations unclear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.