The repository includes tests and a matching README, with no install-time scripts. It lacks security scanning and a security policy, while the single maintainer and quiet recent commit history leave limited ongoing-maintenance evidence.
66%
Total Score
67
100
83
75
Only one registry account has publish access, which limits publishing redundancy. The organization-owned repository provides some compensating project backing, so this is a caution rather than a severe risk.
The package has only 3 releases over about 2 years and 1 release in the last 12 months, with a median interval of about 346 days. This indicates slow maintenance rather than abandonment, so it is a caution.
There were no commits and no active maintainers in the last 3 months, leaving limited evidence of ongoing maintenance after the latest release.
The repository has 0 stars, forks, and watchers. This is weak supporting evidence, but popularity alone does not outweigh the package's tests, licensing, and active non-archived status.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.16 | — | — |
symfony/process Version ^4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.