Checks prefer-lowest more strictly. Add-on for CI.
65%
Total Score
caution
Usable with caveats: registry releases stopped in 2021 and recent work is concentrated in one contributor.
The repository is owned by an individual rather than an organization, so the single-maintainer and concentrated-activity concerns are not offset by visible organizational backing.
The latest registry release was in November 2021, with no releases in the last 12 months; this is a meaningful transparency and freshness concern, though the repository shows later activity.
All recent commits came from one contributor, creating a concentrated maintenance dependency for this user-owned project.
There was one commit from one active maintainer in the last three months; this indicates some maintenance but little recent development capacity.
Composer build tooling is present, but no security-scanning tool was detected; this is a minor process gap rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version ^1.4 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.