The stable MIT package has a README, no install scripts, and a matching non-archived repository. Its tiny audience and absent security tooling leave less evidence of mature ongoing support, while release and commit activity are sparse.
62%
Total Score
75
83
75
Only two releases have appeared over about 22 months, with a median interval of about 18 months and one release in the last year. This indicates slow maintenance, though a recent release provides some evidence the package is not abandoned.
There were 0 commits and 0 active maintainers in the last three months. The recent release push is some compensating evidence, but the current absence of development activity still raises maintenance risk.
The repository has only 2 stars, 0 forks, and 3 watchers. Popularity is supporting evidence rather than a verdict, but these numbers provide little independent evidence of broad review or community support.
Composer is used for builds, but no security scanning tools are configured. The missing scanning is a transparency and hygiene gap, not evidence that the package is unsafe.
The repository has no security policy. For a plugin handling attachment downloads and uploads, this leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.