This release appears generally suitable to depend on: it is a stable, non-deprecated version with regular releases over the past 88 days, an active non-archived repository, substantial source and test scaffolding, and a clear organization-backed mirror relationship to the upstream project. The main concerns are that all six recent commits came from one contributor, the repository has no detected security scanning or security policy, and several workflows use write permissions; these reduce transparency and operational resilience but do not outweigh the demonstrated release cadence and project structure.
78%
Total Score
63
100
89
80
One contributor made 100% of the six recent commits, creating a genuine continuity risk even though organization ownership may allow maintenance handoff.
There were 6 commits in the last 3 months, showing ongoing activity, but only one active maintainer produced them; this is positive activity with limited demonstrated redundancy.
There were no new or merged pull requests and no issue activity in the last month; this does not show abandonment by itself, but it provides little evidence of community maintenance or feedback handling.
The repository has zero stars, forks, and watchers. For a new automated mirror this is weak supporting evidence rather than a decisive health problem, especially given the release and scaffolding signals.
Composer build tooling is present, but no security scanning tools were detected. The build setup is therefore established while security-process transparency remains limited.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.