This release appears healthy and reasonably safe to depend on: it is actively developed, has frequent releases, an unarchived and correctly linked repository, substantial source and test coverage in the repository, documented licensing and security policy, and automated build and security tooling. The main concerns are its relatively young age, pre-1.0 versioning, very concentrated recent commit activity (357 of 358 commits from one contributor), low repository popularity, and a workflow without top-level token permissions; these warrant monitoring but do not outweigh the strong maintenance and transparency evidence.
82%
Total Score
80
100
89
90
Only one registry account has publish access, which is a concentration concern. However, the repository is organization-owned and shows two active maintainers in recent commit activity, so registry access concentration is partly compensated by project backing.
Recent activity is highly concentrated: one contributor made 357 of 358 commits, or about 99.7%, while the second made one. The organization backing provides some handoff capacity, but the observed concentration remains a genuine maintenance-continuity risk.
The repository has only 7 stars, 4 forks, and 3 watchers. Low popularity is supporting caution about external adoption and resilience, but it is not decisive because popularity alone does not establish package health.
The only workflow lacks top-level token permissions, and no read-only or job-level permissions are declared. Although no write permissions are explicitly requested, the absence of an explicit restrictive policy is a workflow-hardening gap.
Version 0.7.2 is not a stable major release, so the API may still evolve before 1.0. However, it is not marked prerelease and recent releases have not used prerelease versions, which partly offsets the maturity concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/cache Version ^3.0 | — | — |
symfony/yaml Version ^7.0 || ^8.0 | — | — |
psr/http-message Version ^2.0 | — | — |
psr/event-dispatcher Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.