The repository has recent activity, but all recent commits come from one contributor and the workflow leaves both actions unpinned. MIT licensing, tests, release notes, Composer tooling, and no install scripts provide useful safeguards.
65%
Total Score
70
100
94
75
Only one account has registry publishing access. Since the project is user-owned rather than organization-owned, this reflects a thin publishing base, though repository activity shows the maintainer is still active.
The package has 13 releases since January 2015, but none in the last 12 months and the latest registry release was in October 2023. This is a meaningful maintenance concern, although recent repository commits provide some compensation.
One contributor made all recorded commits in the last three months, creating a concentrated maintenance dependency. No organization backing or second active contributor is provided to offset that concentration.
There is one open issue and two open pull requests, but no issues or pull requests were closed in the last month. This is a modest sign of limited visible project throughput.
The repository has no security policy. This is a modest transparency and vulnerability-reporting gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
donatj/flags Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.