The project has tests, a clear MIT license, and a repository that matches the package. Maintenance evidence is weak after three months without commits, while security scanning is absent and both workflow actions are unpinned.
62%
Total Score
33
100
83
67
The repository recorded zero commits and zero active maintainers over the last three months, a meaningful maintenance and abandonment concern despite the recent push timestamp and release history.
The registry and repository are owned by the same individual account; this is coherent ownership, but it does not provide organizational backing.
There are no open issues or pull requests, but there was also no issue or pull-request activity in the last month, leaving limited evidence of community maintenance.
The repository has only 1 star, 0 forks, and 1 watcher, offering little external adoption evidence; popularity is supporting evidence rather than a verdict.
Composer is used for builds, but no security scanning tool is configured, leaving a repository security-hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.3 | — | — |
opis/json-schema Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.