The README and tests make adoption straightforward, and the repository is linked to the package. However, its only release has had no recorded commits for about six months, while workflow actions are unpinned and no security policy is present.
60%
Total Score
50
100
88
75
The repository is owned by the individual user JanSuchanek, so the single-user backing provides less organizational continuity than an established project organization.
This is the package's only release, published about six months ago, so there is little evidence of sustained maintenance or release maturity.
No commits and no active maintainers were recorded in the last three months, which is a meaningful maintenance concern for a package whose only release is about six months old.
Composer build tooling is present, but no security-scanning tooling was detected; this is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no security policy, leaving no documented channel or process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.