Usable with caveats: it has a six-year release history, regular recent releases, tests, and organization backing. The linked repository has only one recent contributor and does not identify this package in its README, which makes ownership and continuity worth checking before adoption.
72%
Total Score
67
81
83
All 2 recent commits came from one contributor, so maintenance continuity currently depends on a single active individual. Organizational ownership provides some fallback, but no second recent contributor is shown.
The repository received 2 commits in the last 3 months, showing some recent maintenance, but the activity is limited for a production extension.
The repository name does not match the full package name and its README does not mention the package. Although the mismatch may reflect the vendor namespace, the missing README reference leaves package-to-repository ownership less transparent.
The repository has 5 stars and 1 fork, indicating limited community adoption. Popularity is only supporting evidence, so this modest footprint lowers confidence more than it affects the health verdict.
Composer build tooling is present, but no security-scanning tool was detected. The absence is a transparency gap, though it is partly offset by the lack of risky workflow activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.