Clear documentation, a license, and a focused dependency set reduce adoption friction. There is no security policy or repository security scanning, so maintenance risk remains material.
40%
Total Score
50
100
75
83
The package has had no release in over four years, and it recorded zero releases in the last 12 months. That is strong evidence of stagnation for a dependency tied to an evolving framework.
There were zero commits and zero active maintainers in the last three months, consistent with the repository having been inactive since June 2022. This materially raises abandonment and compatibility risk.
There were no new or closed issues or pull requests in the last month, while six issues remain open. This suggests limited current support activity, though the signal is weaker than the long-term commit gap.
Composer build tooling is present, but no security scanning tools were detected. The build setup is appropriate, while the missing security automation is a modest transparency and maintenance gap.
The repository is not archived, but its last push was over four years ago; the non-archived status provides only limited reassurance against the stronger inactivity evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.