Usable with caveats: the package is clearly identified, licensed, stable, and recently released with a useful README and no runtime dependencies. Maintenance is concentrated in one contributor, with only one commit in the last three months and limited security-policy and workflow-permission hygiene.
68%
Total Score
50
100
94
80
The registry lists one maintainer, consistent with the repository's user ownership but leaving little visible publishing redundancy when combined with the one-contributor recent activity.
All recent commits came from one contributor, giving the project a single-person maintenance dependency. Because the repository is user-owned rather than organization-owned, there is no provided organizational backing to offset that concentration.
Only one commit was recorded in the last three months from one active maintainer. That is a real maintenance concern, although the recent release and unarchived repository provide some compensating evidence.
Composer is used for builds, but no security scanning tools were detected. For a small utility this is a hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.