Usable but with real maintenance risk: the registry has only one release and the source repo hasn’t had any commits in the last 3 months. Packaging is solid (license detected and tests included), but there’s no security policy or CI workflow data to show active hardening.
58%
Total Score
50
100
80
50
This package has only one recorded release (latest and first are the same) and none in the last 12 months, which suggests a low maintenance cadence and higher drift risk.
The repository shows 0 commits in the last 3 months and 0 active maintainers over that window, indicating stalled day-to-day upkeep.
Composer is present as a build tool, but there is no detected security scanning tooling; that limits evidence of proactive security hygiene.
No security policy file is present in the repository, which weakens the transparency path for vulnerability reporting/handling.
The audit found zero GitHub Actions workflows to analyze, so there’s no observable CI/workflow hardening signal (this is a coverage gap, not a confirmed weakness).
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.