Tests, a changelog, and organization backing provide useful continuity. The license mismatch and absent security policy add transparency concerns, alongside the long maintenance gap.
58%
Total Score
75
100
81
88
The artifact contains an Apache-2.0 license file, but the manifest declares the package proprietary; that mismatch requires clarification before adoption.
The package has 42 releases since July 2019, but none in roughly 5 years and 6 months; this is a substantial abandonment concern.
There were no commits and no active maintainers in the last 3 months, consistent with a project that has been inactive for roughly 5 years and 5 months.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest maintenance and verification gap.
The repository has no security policy, making vulnerability reporting and response expectations less transparent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.