The package is clearly licensed and its repository matches the published package. Maintenance has gone quiet, and the release workflow uses three unpinned actions plus installs a package outside a lockfile. Pin this version only if the older codebase remains suitable for your application.
55%
Total Score
67
86
50
The package has 25 releases over more than 11 years, but none in the last 12 months; the latest release was in July 2024. The long history helps, but current release activity is weak.
The repository had zero commits and zero active maintainers in the last 3 months. Combined with no releases in the last year, this indicates little current maintenance capacity.
There were no new or closed issues or pull requests in the last month. With no recent commits, this supports the picture of a quiet project rather than active upkeep.
The project uses Composer build tooling, but no security-scanning tools were detected. This is a modest transparency gap for ongoing maintenance, not a standalone severe risk.
The repository has no security policy. That reduces transparency for reporting and handling vulnerabilities, although it is not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.