Tests, licensing, and a matching organization-owned repository improve transparency. All 14 workflow actions are unpinned and no security policy is published, so maintenance hygiene remains limited.
58%
Total Score
50
100
83
75
There were zero commits and zero active maintainers in the last three months, a concrete sign that maintenance may have slowed or paused.
The package has eight releases over about two years, but only one release in the last 12 months; this indicates a notably slower delivery cadence.
There are 11 open issues with no issues or pull requests opened or closed in the last month, suggesting limited recent issue resolution.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these figures provide little external adoption signal.
Composer build tooling is present, but no security scanning tools were detected, leaving automated security hygiene unconfirmed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/cache Version ^3.0 | — | — |
psr/container Version ^2.0 | — | — |
sebastian/diff Version ^6.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.