The package has a clear MIT license, tests, a matching organization-owned repository, and no install-time scripts. Its 0.x version, long registry release gap, absent security policy, and unpinned workflow actions leave meaningful maintenance and build-hygiene concerns.
58%
Total Score
75
100
75
75
The package has five releases, but none were published in the last 12 months; the latest registry release is about 17 months before collection, which indicates a substantial release gap.
There were no commits and no active maintainers in the three months before collection, which weakens evidence of ongoing development even though the repository is not archived.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest repository hygiene gap.
The repository has no security policy, reducing transparency about how maintainers handle vulnerability reports.
The latest version is not a prerelease, but it remains on the 0.x major line, so API maturity is less established than for a stable major release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
imedge/json Version >=0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.