Clear documentation, tests, and release notes make the package straightforward to evaluate. The project is young, with only two releases, two recent commits, and all recent work from one contributor. Workflow actions are also unpinned, creating a modest reproducibility concern.
68%
Total Score
50
100
88
75
The repository is owned by an individual rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
The package is young at 110 days and has only two releases, with a median interval of about 41 days. This is limited evidence of long-term maintenance, though the recent release activity is a positive counterweight.
One contributor made all two commits in the last three months, leaving maintenance highly concentrated in a single person.
Only two commits were recorded in the last three months. Recent activity exists, but the small volume provides limited evidence of sustained maintenance.
Composer build tooling is present, but no security scanning tool was detected. For a small package this is a hygiene gap rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.