The project has a clear README, tests, release notes, and recent repository activity. Unpinned CI actions and the absent security policy leave modest workflow and transparency gaps.
69%
Total Score
67
100
78
75
The package and repository are owned by the same individual account, so there is no organizational backing to compensate for concentrated maintenance.
The package is mature at about six years old but has only five releases and one release in the last 12 months, indicating a deliberately slow cadence rather than abandonment because the latest release is recent.
All 11 recent commits came from one contributor, leaving maintenance and release continuity dependent on a single person.
The repository has one star and no forks, so there is little external adoption evidence; this is a supporting weakness, not a standalone maintenance verdict.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest security-process gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.