This release appears generally suitable to depend on: it is not deprecated or archived, has a recent push, a substantial release history, tests, documentation, a license file, security policy, automated tooling, and workflows without the analyzed dangerous patterns. The main concerns are that it remains a 0.x package, recent commit activity is sparse and entirely concentrated in one contributor, popularity is low, and one workflow has top-level write permissions. These issues indicate limited maturity and bus-factor risk rather than clear abandonment, especially given the organization-owned repository and recent merged pull requests.
78%
Total Score
80
100
89
90
One contributor made all 2 recent commits, giving a top-contributor share of 100% and creating a clear continuity risk. The organization-owned repository partly mitigates the risk because maintenance can potentially be handed off.
Only 2 commits occurred in the last 3 months, showing limited direct commit activity, although the repository was recently pushed and pull-request merges provide compensating maintenance evidence.
The repository has only 4 stars, 2 forks, and 1 watcher. Low popularity is supporting caution about community depth, but it does not by itself make a small actively maintained package unsafe to use.
Two workflows use read-only permissions, but mkdocs.yml has top-level write permissions, which grants more CI token authority than necessary and warrants review.
The assessed version is a non-prerelease 0.4.1, but the 0.x major version signals API maturity and compatibility risk for dependents.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/http Version ^1.11 | — | — |
react/async Version ^4.3 | — | — |
symfony/cache Version ^7.3 || ^8.0 | — | — |
psr/simple-cache Version ^3.0 | — | — |
fyennyi/async-cache-php Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.