This is a mature, actively maintained and transparently published package: it has existed since 2017, has 220 releases, 12 releases in the last 12 months, a recent release, stable versioning, a matching repository, and substantial recent commit activity. The main adoption risks are concentrated maintenance in one contributor, low repository popularity, no repository security policy or security-scanning tooling, and workflows with top-level write permissions. These concerns warrant review of the project’s continuity and CI configuration, but they do not outweigh the strong release cadence, non-archived repository, licensing, repository tests, and clean workflow-risk indicators.
78%
Total Score
70
100
89
80
Only one registry account has publish access, which limits publishing redundancy; this is partly mitigated by the matching source repository and observed ongoing activity.
The repository is owned by an individual user rather than an organization, so there is no organizational maintenance redundancy to offset the concentrated contributor base.
All 34 attributed recent contributor commits come from one contributor, creating a meaningful continuity and bus-factor risk for a user-owned project.
The repository has modest visibility with 8 stars, 6 forks, and 3 watchers. This is a supporting weakness rather than a decisive health problem because activity and release history are strong.
Composer build tooling is used, but no security-scanning tooling is configured, leaving a security-process gap that should be considered when adopting the dependency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.