Documentation and packaging are in good shape. The single-maintainer project has no security policy or scanning tools, while its 0.x status adds longer-term adoption risk.
70%
Total Score
83
100
81
75
All 60 recent commits came from one contributor, creating a meaningful continuity risk if that maintainer becomes unavailable.
The repository has 1 star, 1 fork, and no watchers, indicating limited external adoption; active commits partly compensate, so this is supporting caution rather than a primary verdict.
Composer is used for builds, but no security scanning tools are configured, leaving a notable maintenance and security-hygiene gap.
The repository has no security policy, so there is no documented process for reporting and handling vulnerabilities.
Version 0.6.1 is not a stable major release, so compatibility may still change; however, recent releases show active development and no prerelease pattern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.3 | — | — |
vimeo/vimeo-api Version dev-master | — | — |
google/apiclient Version ^2.0@dev | — | — |
james-heinrich/getid3 Version 2.0.x-dev | — | — |
robthree/twofactorauth Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.