Tests, an MIT license, and organization backing improve transparency, but the single registry maintainer, eight open pull requests, and no security policy limit ongoing support. Its small user base adds little evidence of broad adoption.
57%
Total Score
50
83
75
The repository recorded no commits and no active maintainers in the last 3 months, with the last push about 2 years and 6 months ago. This strongly indicates limited current maintenance.
Only one registry publishing maintainer is listed, which creates some operational concentration risk. The repository is organization-owned, so this is less concerning than a one-person project with no organizational backing.
The package has had no releases in the last 12 months, and its latest release was about 2 years and 9 months ago. This is a meaningful maintenance concern, although the package has nine releases over its longer history.
There are eight open pull requests, with no new or merged pull requests in the last month. This suggests unresolved maintenance work despite the absence of open issues.
The repository has only 2 stars, 2 forks, and 5 watchers, providing little supporting evidence of broad review or community involvement. Low popularity alone does not make a small package unhealthy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cache/cache Version ^0.1.0 | — | — |
dms-org/core Version ^0.9.0 | — | — |
marcj/topsort Version ^1.0.0 | — | — |
laravel/framework Version ^8.0 | — | — |
league/oauth2-google Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.