Tests, release notes, and security scanning provide a solid baseline. The short history and one-person activity leave limited evidence of durable maintenance, while the workflow audit found a high-confidence credential-permission issue.
58%
Total Score
50
100
83
75
Only one registry maintainer is listed. This is consistent with the user-owned repository but leaves limited publishing redundancy.
The repository is owned by an individual rather than an organization, so there is no shown organizational handoff capacity to offset the concentrated maintenance base.
The package is only 58 days old and has two releases, so there is limited evidence of a sustained release pattern, although recent publication shows the project is active.
All recent commits came from one contributor, so maintenance depends entirely on a single person; the repository is user-owned rather than organization-backed.
Only one commit from one active maintainer was recorded in the last three months, providing weak evidence of ongoing maintenance beyond the recent release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/composer Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.