The release includes tests, release notes, a matching repository, and an explicit LGPL license. Its small single-contributor project and unpinned workflow actions leave less maintenance and build-integrity margin.
67%
Total Score
50
100
94
50
The package and repository are owned by the same individual account, and the repository is not archived, but no organization backing is shown to broaden maintenance capacity.
One contributor made all commits during the last three months, leaving maintenance dependent on a single active person. The repository is user-owned, so there is no organization backing shown to offset that concentration.
Only one commit was recorded in the last three months, so current maintenance activity is limited even though the repository was recently updated.
Composer build tooling is present, but no security-scanning tool was detected, reducing automated coverage for dependency or build issues.
The repository has no security policy, leaving reporting and handling expectations undocumented. This is a transparency gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
jord-jd/do-file-cache Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.