It includes tests, a README, and no install-time scripts. The GPL license mismatch and unpinned workflow actions reduce confidence in maintenance and publishing hygiene.
62%
Total Score
50
81
67
The artifact declares GPL-3.0-or-later, but its detected LICENSE file is GPL-2.0. The release is licensed, yet the mismatch creates uncertainty about the terms consumers should follow.
There have been 18 releases, but none in the last 12 months and the latest release was over three years ago. That materially raises abandonment and staleness risk.
The repository recorded zero commits and zero active maintainers in the last three months. This conflicts with the recent push timestamp and leaves current development capacity uncertain.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than a standalone adoption blocker.
The repository has no security policy. For a library, that weakens the documented process for reporting and handling security issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
datagutten/tools Version ^1.11 | — | — |
symfony/filesystem Version ^4.3|^5.0|^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.