The repository includes tests, a changelog, clear documentation, and a security policy. Build references are unpinned and no security scanning is configured, which weakens maintenance hygiene despite the package's simple dependency profile and valid license.
62%
Total Score
50
100
89
100
The package and repository are owned by the same individual account rather than an organization, so the single-person ownership context provides limited continuity if the maintainer becomes unavailable.
The package has 23 releases since November 2021, but none in the last 12 months; the latest release was in October 2023, indicating a prolonged release pause.
There were zero commits and zero active maintainers in the three months measured, consistent with the long registry release pause and raising abandonment risk.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is consistent with a quiet project but does not by itself prove abandonment.
The repository uses Make and Composer, but no security scanning tools are configured. The missing scanning is a maintenance-hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.