Documentation and licensing are in place, with a focused dependency set and no install scripts. The repository has had no commits or pull requests in three months, and its workflow uses two unpinned actions.
68%
Total Score
50
100
88
83
The package and repository are owned by the same individual account. This is consistent ownership evidence, but it does not provide the redundancy of organization backing.
There are 11 releases in the last 12 months, but all were published within one day, so the history shows an initial release burst rather than sustained cadence. This is a modest maintenance concern.
The repository recorded zero commits and zero active maintainers over the last three months. For a newly released fork this may reflect stabilization, but it still leaves maintenance continuity unproven.
There were no new or merged pull requests and no new issues in the last month. This is consistent with a quiet project but provides little evidence of ongoing maintenance.
Composer is used as the build tool, but no security scanning tool is configured. The missing scanner is a hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.