The project has a clear README, repository tests, stable releases, and organizational backing. Its maintenance appears inactive, and the license mismatch plus unpinned workflow dependency reduce transparency and build confidence.
54%
Total Score
75
79
75
The artifact declares MulanPSL-2.0, while the repository license file was detected as MIT. The release is licensed, but the mismatch creates a meaningful transparency and compliance concern.
The package has 23 releases since April 2019, but none in the last three years; the latest release was in June 2023. This materially raises maintenance and abandonment concerns.
There were no commits and no active maintainers in the last three months, consistent with the last repository push being in October 2023. This is a strong sign of inactive maintenance.
Composer build tooling is present, but no security scanning tools were detected. This is a modest process gap for a package that has otherwise been inactive.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.