The package has a clear README, release notes, matching source repository, and an MIT license. Its small project has no security policy or scanning, which leaves maintenance and security transparency weaker.
58%
Total Score
50
86
75
The latest release was published about 15 months ago, and there were no releases in the preceding 12 months. With only five releases since May 2024, ongoing maintenance appears limited.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long gap since the latest release. This raises maintenance and abandonment risk for a package that performs database updates.
Composer is used as the build tool, but no security-scanning tools are configured. The absence of scanning weakens automated security hygiene for this dependency.
The repository has no security policy, so there is no documented channel or process for handling vulnerabilities. This is a transparency gap, though it is not evidence of a security flaw by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.