The package includes clear documentation, a license, tests in its source repository, and conventional Composer tooling. Its single release and zero recent commits leave maintenance uncertain, while the workflow uses nine unpinned actions and the README does not mention this package.
38%
Total Score
33
100
75
75
This package has only one release, published 647 days ago, with no releases in the last 12 months. That is strong evidence of limited ongoing maintenance.
The repository had zero commits and zero active maintainers in the last three months. Combined with one release, this materially raises abandonment risk.
The registry and repository are owned by the same individual account, with no organization backing shown. This is not inherently unsafe, but it indicates a thin ownership structure when activity is absent.
There were no new or closed issues or pull requests in the last month, and no pull requests were open. This provides no evidence of active project engagement.
The repository name matches the package, but its README does not mention the package name. That weakens confidence that the repository documentation is specifically maintained for this published package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.