A security policy, repository tests, release notes, and minimal runtime dependencies support responsible use. The organization backing helps offset the small recent contributor base, but ongoing activity remains limited.
70%
Total Score
67
100
88
100
The package has existed since 2013 with 17 releases, but it had no release in the last 12 months and its latest release was about 14 months ago, indicating slower maintenance.
One contributor made all commits in the last three months. Organization backing provides some handoff capacity, but no second active contributor is shown to offset this concentration.
Only one commit was recorded in the last three months, showing limited recent maintenance activity even though the repository was recently pushed.
Composer build tooling is present, but no security scanning tool was detected; this is a modest transparency gap rather than evidence of unsafe code.
The workflow audit completed cleanly with no reported findings or untrusted checkout and injection sinks. Its single action reference is unpinned, which is a minor reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.