Healthy and usable for dependency adoption, with a small maintenance and documentation caveat. The repository is active, non-archived, organization-backed, and has two active contributors, but releases are infrequent and the README is very minimal for a library with a broad API.
78%
Total Score
83
100
81
83
The release includes a README, while the absence of tests and a changelog in the published artifact is normal packaging practice. However, the README is only 103 characters and provides little guidance for consumers of this library.
The package has only 2 releases over 261 days, with a median interval of about 75 days. This is limited maturity evidence, but it is not an abandonment signal because the repository shows recent activity.
Two contributors were active, but one made 85% of the recent commits. The second contributor and organization backing provide some handoff capacity, so this is only a modest continuity concern.
The repository uses Composer for builds, but no security scanning tools were detected. The missing scanning is a transparency gap, though it is not by itself evidence that the package is unsafe.
The repository has no security policy. That weakens vulnerability-reporting transparency, but the impact is limited for this small package and is partly offset by its active repository.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/protobuf Version ^4.31 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.