Healthy and reasonable to depend on. It has a long release history, a current stable release, active organizational backing, tests, documentation, and security tooling; recent development is limited to one commit from one contributor, so continued maintenance should be monitored.
82%
Total Score
67
100
100
90
All one recent commit came from a single contributor, which creates concentration risk; the organization-owned repository provides some capacity to hand maintenance to others.
Only one commit was recorded in the last three months, by one active maintainer; this is a meaningful sign of limited recent development, although the recent release history provides some compensation.
Neither analyzed workflow declares top-level token permissions, leaving workflow privilege limits less explicit than ideal; no workflow has declared top-level write access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.