The codebase has tests, release notes, a clear MIT license, and only one runtime dependency. The main concern is that maintenance stopped about four years ago, with no recent commits or releases, while workflow references remain unpinned.
58%
Total Score
88
100
78
75
The package has four releases but no release in about four years, which is a meaningful maintenance and abandonment concern despite the stable 1.2 version.
There were no commits and no active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
The repository has only two stars, no forks, and no watchers, indicating limited external adoption or review; this is supporting caution rather than a decisive health verdict.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency and maintenance gap for an otherwise small package.
The repository is not archived, but its last push was about four years ago, so the lack of archival does not demonstrate active maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.