This release appears generally suitable to depend on: it is licensed, non-deprecated, stable, linked to a matching organization-owned repository, and has a recent release cadence with six releases over 161 days. The repository is not archived and shows recent activity, but maintenance evidence is still narrow: only two commits in the last three months came from one contributor, the repository has no security scanning or security policy, and its workflow does not declare top-level token permissions. The package is relatively young, so its long-term maintenance track record remains limited; dependency risk is otherwise low because it declares only PHP as a runtime dependency.
78%
Total Score
70
100
89
75
All two recent commits came from one contributor, creating a concentrated maintenance dependency; organization ownership partly mitigates handoff risk but does not remove the thin observed contributor base.
Two commits were made in the last three months by one active maintainer, demonstrating recent maintenance but at a low pace.
There are no open issues or pull requests and no activity in the last month. This is not inherently negative, but it provides little evidence of an active user or maintainer feedback loop.
The repository has only 2 stars and 1 fork, indicating limited adoption evidence; this is supporting context rather than a decisive health problem for a small package.
Composer build tooling is present, but no security scanning tools are configured, leaving a security-hygiene gap that is relevant to dependency maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.