This release appears healthy and reasonable to depend on: it is actively maintained, has a stable 1.5.0 release line, a clear MIT license, a matching and well-documented source repository, reproducible-looking Composer metadata, and recent repository activity with 66 commits over three months. The main concerns are that the package is young, nearly all recent commits come from one contributor, and the repository lacks a security policy; however, the second active contributor, repository tests, readme, changelog, dependency tooling, and restrictive workflow permissions provide meaningful compensation. The limited popularity is not itself a dependency-health problem.
82%
Total Score
70
100
94
90
Only one registry account has publish access, which creates publishing continuity risk; this is partly offset by the active source repository and its second recent contributor.
The repository is owned by an individual rather than an organization, so the concentrated maintainer activity represents a genuine single-owner continuity risk.
Seven releases in 88 days, with a median interval of about 15 days, show active early maintenance, though the package has limited long-term history.
Commit activity is highly concentrated, with one contributor responsible for about 98.5% of recent commits; the presence of a second contributor reduces but does not remove this continuity risk.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.