The package is clearly licensed, documented, and has recent repository activity. Its long release gaps, two recent commits from one contributor, and missing security policy leave maintenance capacity and operational transparency limited.
62%
Total Score
50
88
75
Only two releases have appeared since the first release about 5 years ago, with a median gap of about 4 years and 10 months; one release in the last 12 months provides some current activity but not a dependable cadence.
One contributor made all two commits in the last 3 months, leaving maintenance dependent on a single active person and providing no demonstrated handoff capacity.
The repository recorded only two commits in the last 3 months. This is evidence of some current activity, but the volume is too low to demonstrate strong ongoing maintenance.
Composer is used for builds, but no security scanning tool was detected. That is a modest transparency and maintenance weakness rather than a severe risk.
The repository has no dedicated security policy. The package README provides an email contact, which partly compensates for the missing formal policy but does not document a full vulnerability process.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.