The small project footprint and lack of security scanning reduce confidence for long-term support. Repository tests, matching source, and a clear MIT license provide useful safeguards, but the package has not released since June 2023.
55%
Total Score
50
100
69
83
The latest release was over three years ago, with no releases in the last 12 months; only three releases exist since September 2022. This is the strongest maintenance concern, though the repository is not archived.
The repository is owned by an individual user rather than an organization, so the package appears to rely on a single personal project rather than broader institutional backing.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a small project but provides no evidence of active community maintenance.
The repository has two stars, no forks, and one watcher. This is limited supporting evidence and indicates a thin external user base, though popularity alone does not determine health.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a modest transparency and maintenance gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
grpc/grpc Version ^1.52.0 | — | — |
nesbot/carbon Version ^2.62 | — | — |
google/protobuf Version ^3.21 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.