This release appears to be a healthy dependency: it is not deprecated or archived, has a recent repository push, regular release activity, a matching and package-referencing repository, documented tests, and clear MIT licensing. The organization-owned project has two active contributors and recent merged pull requests, although 92.3% of recent commits come from one contributor and the repository lacks security scanning and a security policy; these are meaningful but not severe concerns given the continued release and commit activity. The 0.x version indicates API stability is not yet at a stable-major level, so consumers should expect some compatibility risk.
82%
Total Score
90
100
89
90
Recent commits are highly concentrated: one contributor made 12 of 13 commits, or 92.3%. The second contributor remains active and the repository is organization-owned, which partly mitigates but does not eliminate the continuity risk.
Composer build tooling is present, but no security scanning tools are configured, leaving a security-hygiene gap in the development process.
The repository has no published security policy, which reduces transparency around vulnerability reporting and response.
The current version is a non-prerelease 0.7.3 with no recent prerelease releases, but the 0.x major version still signals that API compatibility may not yet be fully stable.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.