The package has clear usage documentation, a simple runtime dependency profile, and a reproducible build setup. Workflow review found no untrusted checkouts or broad write permissions, though the missing security policy leaves less guidance for reporting issues.
78%
Total Score
67
100
93
75
One contributor made all recent commits, which creates concentration risk. The organization-owned repository provides some handoff capacity, so this is a maintenance caution rather than a severe abandonment signal.
Only one commit was recorded in the last three months, showing limited recent development activity even though releases and pull-request merges indicate the project has not stopped entirely.
The project uses Composer for builds, but no security-scanning tool was detected. The missing scanning coverage is a modest transparency and maintenance gap, not evidence of an unsafe package.
The repository has no security policy, leaving vulnerability-reporting expectations and response guidance undocumented. This is a transparency gap, but it is not evidence that the package is unmaintained.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.