The package includes useful documentation, release notes, and clear organizational ownership. Its very small release history and absent recent maintenance make future compatibility and support uncertain.
55%
Total Score
75
75
50
Only two releases were published, both in January 2024, with no release in the following 976 days. That leaves little evidence of ongoing maintenance, although the package is not marked deprecated.
There were zero commits and zero active maintainers in the last three months, consistent with the long release gap. Organizational ownership provides some backing, but no observed recent work compensates for the maintenance pause.
The repository uses Composer for builds, but no security scanning tools were detected. This is a transparency and hygiene gap, not evidence that the package is unsafe.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. The organization backing the repository is a positive context, but it does not replace a published process.
Version 0.2.0 is not a prerelease, but the project remains below 1.0 and has only two releases. This suggests a less mature compatibility commitment than an established stable-major package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.