The MIT license, extensive test suite, security policy, and organization-backed repository improve confidence. Maintenance has slowed to one release in the last year and no commits in three months, while workflow actions are all unpinned.
67%
Total Score
75
88
75
The package has 52 releases over about four years, but only one release in the last 12 months; the recent slowdown lowers maintenance confidence despite the long release history.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign of slowed maintenance even though the release history shows prior activity.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not a severe adoption blocker.
The sole workflow was fully analyzed and scopes permissions at job level, with no untrusted checkout or script-injection findings. However, all five action references are unpinned, leaving avoidable update and supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
district5/date Version >=3.0.4 | — | — |
mongodb/mongodb Version * | — | — |
district5/mondoc-builder Version * | — | — |
district5/mondoc-encryption Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.