This release appears to be a healthy, actively maintained dependency: it is not deprecated or archived, has a stable major version, and shows a strong release cadence with 8 releases in 173 days. The linked organization-owned repository matches the package and documents it, contains tests and complete source scaffolding, and has recent activity from four contributors, although commits are concentrated in one contributor. The main reservations are the absence of repository security scanning and a security policy, incomplete top-level workflow permission declarations, and modest repository popularity; these are hygiene concerns rather than evidence of abandonment. The package is licensed, has no install-time lifecycle scripts, and has a small runtime dependency surface.
88%
Total Score
90
100
89
80
One contributor made about 81% of the 27 recent commits, creating concentration risk, although three additional contributors remained active and the repository is organization-owned.
The repository has only 5 stars and 1 fork, so external adoption evidence is limited; this is supporting context and does not outweigh the strong maintenance and release signals.
Composer build tooling is present, but no security-scanning tools were detected, leaving a security-hygiene gap.
The repository has no security policy, which reduces transparency about vulnerability reporting and handling.
Two workflows lack top-level permission declarations and one workflow has top-level write permissions; explicit least-privilege configuration would improve CI security hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.