The project has organization backing, tests, a matching license, and a release for this version. Maintenance is currently quiet, with no commits in three months, while all four workflow actions are unpinned and the repository does not clearly identify this package.
62%
Total Score
67
100
79
75
The package has existed since 2018 but has only 12 releases, with one release in the last 12 months and a median interval of about 322 days. This indicates a slow release cadence, though the latest release is recent.
There were zero commits and zero active maintainers in the last three months. The recent release and organization backing soften the abandonment concern, but current maintenance capacity is still unclear.
The repository has five open issues and two pull requests, but no new or closed issues and no merged pull requests in the last month. This suggests limited current interaction.
The repository name does not match the package name and its README does not mention the package. Although the repository is under the expected organization, this weakens package-to-source traceability.
Composer is used for builds, but no security scanning tools were detected. The missing scanning coverage is a modest transparency and maintenance gap, not evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
grpc/grpc Version ^v1.13.0 | — | — |
psr/cache Version ^1.0.1||^2.0.0||^3.0.0 | — | — |
google/auth Version ^1.3 | — | — |
google/protobuf Version ^v3.25.3||^4.26.1||^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.