A single registry maintainer and no commits in the last three months limit visible maintenance capacity. Tests, release notes, licensing, and a clean workflow audit provide useful support, but missing security scanning and unpinned actions leave transparency gaps.
64%
Total Score
50
100
89
75
The registry namespace and repository owner match, but the backing owner is an individual rather than an organization. Combined with one registry maintainer, this indicates a relatively thin visible ownership base.
The package has existed since January 2017 with 14 releases, but it had no releases in the last 12 months; the latest release was June 10, 2025. This indicates a mature but currently quiet release cadence.
The repository recorded zero commits and zero active maintainers over the last three months. Although the recent release and push show prior activity, the current pause lowers confidence in ongoing maintenance.
There are 67 open issues and 14 open pull requests, while no issues or pull requests were opened or merged in the last month. The backlog and recent inactivity suggest limited current responsiveness.
Composer is used for builds, but no security-scanning tools are configured. The missing scanning is a modest repository hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.