The artifact includes a README, changelog, and several detected license files, while installation has no lifecycle scripts. One registry maintainer and no security policy leave limited visible support for a package that has been inactive for years.
43%
Total Score
25
71
75
The latest release was April 29, 2021, and there were no releases in the last 12 months. Six releases over roughly six years show a long inactive period rather than an actively maintained dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release gap and providing no evidence of current maintenance.
Only one account has registry publishing access. Because the project is backed by an individual user rather than an organization, this indicates a thin publishing base and limited continuity if that maintainer stops working on it.
The linked repository name does not match the package and its README does not mention the package, so the relationship between the published package and source repository is not clearly established.
The repository uses Composer for its build or package tooling, but has no security scanning tools. The explicit build tooling is positive, while the missing scanner is a modest hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.