This is a generally healthy package to depend on: it has a stable MIT-licensed release, a correctly matching organizational repository, comprehensive repository tests, a non-archived source repository, and a release published very recently. The main concerns are modest maintenance velocity—only one release in the last 12 months and no commits or active maintainers in the last 3 months—and incomplete repository security hygiene, including no security policy and no explicit workflow token permissions. These issues warrant monitoring but do not currently indicate abandonment or an unfit dependency.
78%
Total Score
75
100
89
80
Only one registry account has publish access, which is a limited publishing base. However, the repository is owned by an organization, so the short registry maintainer list is not by itself strong evidence of weak project backing.
The package has existed for 3141 days with 8 releases and a latest release on the assessment date, but only 1 release in the last 12 months. The recent release is reassuring, while the low annual release cadence suggests maintenance is steady but not highly active.
There were zero commits and zero active maintainers in the last 3 months, which is a meaningful indication of currently low maintenance velocity. This is partly offset by the very recent release and repository push, but the release may not reflect sustained ongoing development.
Composer build tooling is present, but no security scanning tools were detected. The absence of automated security scanning is a repository hygiene gap, though it does not alone make the package unfit.
The repository has no security policy. This reduces transparency about vulnerability reporting and response procedures, although it is a documentation gap rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.