The repository is owned by an organization, includes tests and documentation, and was pushed recently. The small dependency set and read-only workflow permissions help, but two unpinned actions and no security policy reduce confidence for long-term use.
67%
Total Score
75
100
83
83
The package has 9 releases since February 2015, but none in the last 12 months and the latest registry release was over three years ago. This weakens release maintenance evidence despite the repository having a recent push.
The repository has no commits and no active maintainers in the last three months, although it was pushed in January 2026. That recent push does not establish sustained ongoing maintenance.
There is one open issue and two open pull requests, but no issues or pull requests were opened or merged in the last month. This provides limited evidence of active collaboration.
The repository has 6 stars and 6 forks, indicating a small user base. Popularity is supporting evidence only, so this modest count is a minor concern rather than a health verdict.
Composer is used for builds, which fits the package ecosystem, but no security scanning tools are reported. This is a hygiene gap, not evidence that the release is unfit.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.