The README and license make the package understandable and legally usable. Its single beta release and no repository commits or active maintainers since April 2020 leave maintenance and compatibility risk high.
36%
Total Score
0
71
75
The package has only one release, published in April 2020, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency.
There were no commits and no active maintainers in the last three months, consistent with the repository having stopped changing in April 2020. This materially increases abandonment and compatibility risk.
Composer is used as the build tool, but no security-scanning tooling was detected. The missing scanner is a transparency and maintenance concern, though it is less significant than the prolonged inactivity.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This adds a transparency gap for a package intended to run in project build workflows.
The only available version is beta2, and all recent releases are prereleases. That leaves compatibility less established, although the package is not registry-deprecated.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.