Usable with caveats: it has recent releases, an active repository, clear licensing, and documentation, but maintenance is concentrated in one contributor and the project lacks a security policy. Review its dependencies and maintenance plan before relying on it for critical functionality.
72%
Total Score
75
100
88
67
All 3 recent commits came from one contributor, so maintenance depends heavily on a single person. The repository is user-owned rather than organization-owned, providing no shown organizational handoff capacity to offset that concentration.
The repository has only 4 stars and 1 fork, indicating limited independent adoption or review. Popularity is supporting evidence rather than a decisive health measure, so this is a modest concern rather than a severe risk.
Composer is used as a build tool, but no security-scanning tools were detected. The absence of automated security scanning reduces maintenance transparency for a package exposing file, HTTP, authentication, and caching utilities.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap, though it does not by itself show abandonment.
The single workflow has no top-level token permissions declaration. No write permissions were observed, but the missing explicit restriction leaves CI privileges less transparent than they could be.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.