The project has no commits in the last three months, and its repository has no security scanning or security policy. Frequent releases, repository tests, clear licensing, and read-only workflow permissions provide meaningful maintenance and transparency evidence.
82%
Total Score
83
100
83
83
There were no commits and no active maintainers in the last three months. This is a maintenance caution, although the recent release history shows the package is still being published.
The repository has only 2 stars and 1 fork, indicating limited community adoption. Popularity is supporting evidence rather than a health verdict, so this has modest weight.
Composer is used for the build, but no security scanning tools are configured. The missing scanning is a security-process gap, though it does not establish a release defect.
The repository has no security policy, which reduces transparency about vulnerability reporting and response expectations.
Version 0.40.0 is not a stable major release, but it is not a prerelease and recent releases contain no prerelease versions, so the maturity concern is limited.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
flow-php/etl Version self.version | — | — |
elasticsearch/elasticsearch Version ^7.6|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.