The source includes tests and release notes, with a clear MIT license and modest dependency set. Missing security scanning and a security policy reduce confidence in ongoing upkeep.
65%
Total Score
50
100
88
75
The repository is owned by a user account rather than an organization, so there is no organizational backing signal to offset the small maintainer base or quiet recent activity.
The package has 11 releases over about 3 years, with a median interval of about 76 days, but only one release in the last 12 months. This suggests established but slowing maintenance.
There were zero commits and zero active maintainers in the last 3 months. Although the repository had a recent release and push, the current lack of development activity raises abandonment risk.
No issues or pull requests were opened, closed, or merged in the last month, while four issues and two pull requests remain open. This is a modest sign of limited recent project engagement.
The repository uses Make and Composer, but no security scanning tools were detected. Build tooling is present, while security-maintenance practices are less visible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^3.4 || ^4 || ^5 || ^6 || ^7 || ^8 | — | — |
justinrainbow/json-schema Version ^5.2 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.