The MIT license, README, tests, and release notes make the package straightforward to evaluate and use. Its workflow has no detected dangerous patterns, but the action references are unpinned.
68%
Total Score
50
100
88
75
The package and repository are owned by the same individual account, so there is no organization-level backing to offset the concentrated contributor base.
Only two releases have appeared across about 19 months, with one release in the last 12 months. The package is not abandoned, but its release cadence is sparse.
All recent commits came from one contributor, so maintenance depends heavily on a single individual and has limited handoff resilience.
The repository had one commit in the last three months from one active maintainer, showing recent activity but limited maintenance throughput.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.