Usable with caveats: it has a clear license, tests, release notes, build tooling, and a matching source repository. However, the last release was nearly two years ago and there has been no recent commit activity, so future maintenance is uncertain.
68%
Total Score
75
100
94
67
The package has 18 releases since 2017, but its latest release was nearly two years ago and there were no releases in the last 12 months. This indicates materially slowed maintenance despite a previously established release history.
There were no commits and no active maintainers in the last three months. Combined with the old latest release, this is the clearest sign that maintenance may have stalled.
The repository has no published security policy. This is a transparency gap for vulnerability reporting, though it is not by itself evidence that the package is unsafe to use.
Both workflows lack top-level token-permission declarations. No workflow requests top-level write access, which limits the concern, but explicitly restricting permissions would provide stronger supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version ^1.0|^2.0|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.