The package has a small, focused footprint and recent source activity, with clear licensing and tests. Its workflow audit found no risky patterns, though its action references are unpinned.
68%
Total Score
50
100
88
75
The registry package and repository are owned by the same individual account, so there is no organization backing shown to offset the concentrated maintainer base.
The package has existed for about 9 years but only has 7 releases, with one release in the last 12 months and a median interval of about 16 months. This is a meaningful maintenance-cadence caution despite the recent release.
All recent commits came from one contributor, giving the project a top-contributor share of 100%. This concentrates maintenance risk, especially alongside the sparse release history.
There was one commit in the last 3 months from one active maintainer, showing recent attention but limited ongoing activity.
The project uses Composer, but no security-scanning tools were detected. The absence of scanning is a modest transparency and hygiene gap, not evidence of abandonment.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.