The package has a small dependency footprint, tests, and recent releases. Maintenance is concentrated in one contributor, and workflow actions are unpinned; the linked repository remains active.
22%
Total Score
50
100
83
75
Packagist marks the entire package as abandoned and provides no replacement package. This is a severe adoption risk even though the repository is still active.
One contributor made all six commits in the last three months, leaving no demonstrated backup maintainer. This increases continuity risk despite the recent activity.
The repository received six commits in the last three months from one active maintainer. Recent work is positive, but the activity base is narrow.
Composer build tooling is present, but no security scanning tooling was detected. The missing scanning is a modest transparency and maintenance gap.
The repository has no security policy. For a library intended for dependency use, this leaves vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.