The MIT license, substantial README, repository tests, and release notes provide good consumer and project context. However, the last release and commit activity are over four years old, and every workflow action reference is unpinned. Pin 1.0.1 if adopting despite the maintenance gap.
57%
Total Score
75
100
83
83
All four releases arrived within one day, and there have been no releases in over four years. The package may be stable, but this provides little evidence of ongoing maintenance.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no release for over four years.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no additional community-maintenance signal.
Composer is used for the build, which fits the package, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than a standalone severe risk.
No repository security policy was found, reducing guidance for reporting vulnerabilities in a package with no recent maintenance activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.