The codebase is small and clearly tied to this package, with repository tests and a stable release line. Documentation is present, but licensing differs between the declaration and repository file, and several maintenance safeguards are limited.
59%
Total Score
75
81
50
A license is present, but the manifest declares MulanPSL-2.0 while the repository license file is detected as MIT. This mismatch weakens licensing clarity for consumers.
The package declares pre- and post-install/update Composer scripts. These add installation complexity and supply-chain exposure, although the signal provides no evidence that the scripts are harmful.
The package has 64 releases since August 2021, but none in the last 12 months and its latest release was over two years ago. This indicates a meaningful maintenance slowdown despite the previously regular release cadence.
There were zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. This is a direct abandonment concern, though the repository is not archived.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.