The package is clearly licensed, documented, and tested in its repository, with no install-time scripts. Its only release was over three years ago, commit activity is currently absent, and the workflow uses two unpinned actions.
55%
Total Score
50
100
81
67
Registry publishing access is held by one maintainer. For this user-owned project, that indicates a thin publishing base and limited redundancy.
The registry namespace and repository are owned by the same individual account, so the package has identifiable ownership but no organizational backing shown by this signal.
Only two releases exist, both from December 2022, and there have been no releases in the last 12 months. That limited history and prolonged release gap reduce confidence in ongoing maintenance.
The repository had zero commits and zero active maintainers in the last three months. This is direct evidence of currently inactive development.
Composer is used as the build tool, but no security scanning tool is detected. The missing scanner is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
azjezz/psl Version ^1.9|^2.1 | — | — |
vimeo/psalm Version ^4.30 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.