Stable versioning, MIT licensing, tests, and a minimal dependency set support adoption. The organization-backed repository is not archived, but maintenance has gone quiet and workflow references are unpinned. Missing documentation and a security policy add smaller transparency concerns.
58%
Total Score
75
100
79
75
The package includes tests and the repository includes tests, which supports basic project maturity. The missing README reduces consumer guidance for an extension library, while the absent changelog is not a packaging concern by itself.
The latest release was on January 23, 2023, with no releases in the last 12 months and only two releases overall. This is a meaningful maintenance concern, although the stable major version and non-deprecated status provide some context.
There were zero commits and zero active maintainers in the three months measured. This is direct evidence of currently inactive maintenance and raises the risk of delayed fixes.
The repository uses Make and Composer, showing some build structure, but no security scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence of abandonment.
No security policy was found in the linked repository. For a dependency intended for application integration, this weakens the project's vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.