The source is active enough to remain unarchived, has a matching repository, and keeps runtime dependencies minimal. Recent commit activity is empty, all eight workflow actions are unpinned, and the manifest's GPL-2 declaration conflicts with the README's GPL-3 text.
62%
Total Score
67
100
71
75
The manifest declares GPL-2.0-or-later, while the included README says GPL-3.0-or-later; the release is licensed, but the conflicting texts require clarification before adoption.
The package is about 11 months old with three releases, all published within minutes on the first day; this shows initial publication but no sustained release cadence.
There were zero commits and zero active maintainers in the last three months, a concrete sign that maintenance may have stalled.
Six pull requests remain open, with no issues or pull requests merged in the last month; this suggests unresolved maintenance work, though it is not evidence of abandonment by itself.
The repository uses Composer build tooling, but no security scanning tool was detected; this is a modest transparency and maintenance gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.