Maintenance has gone quiet since July 2025, and all six workflow actions are unpinned. MIT licensing, tests, an active repository, and organization backing provide useful counterweight, but the package remains early-stage.
57%
Total Score
50
75
75
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the last push in July 2025, this is the main maintenance risk.
The source repository has tests, which supports basic project discipline. The published artifact has no README, making integration less transparent for consumers of this library.
There have been only two releases over about two years, with no releases in the last 12 months and a median interval of about 371 days. This indicates a slow and immature release cadence.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is consistent with a quiet project but does not by itself prove abandonment.
The project uses Composer build tooling, but no security scanning tools were detected. The missing scanning is a modest transparency gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sop/x509 Version ^0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.