Healthy and suitable to use, with a small maintenance caveat. It has a current stable release, regular release history, a matching repository, clear documentation, and no deprecation or archived-repository concerns. Recent development is limited to one contributor, and the repository has no security policy or scanning tools.
78%
Total Score
50
100
94
90
Only one registry account has publishing access, creating some continuity risk, although registry access records do not measure actual development activity.
The registry namespace and repository owner match, but the owner is an individual rather than an organization; this supports package identity while offering no organizational continuity guarantee.
All 2 recent commits came from one contributor, so maintenance depends entirely on a single person. The repository is user-owned rather than organization-owned, so there is no provided organizational backing to compensate for this concentration.
Only 2 commits were made in the last 3 months by one active maintainer. Recent work exists, but the low volume provides limited evidence of maintenance capacity.
There is one open issue and one open pull request, with one new issue in the last month and no closures, suggesting limited but nonzero project activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0.0|^2.0.0 | — | — |
nyholm/psr7 Version ^1.5 | — | — |
symfony/uid Version ^6.0|^7.0 | — | — |
scheb/2fa-bundle Version ^6.0.0|^7.0.0 | — | — |
web-auth/webauthn-lib Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.