The package includes tests, a substantial README, and a matching source repository. Its single maintainer, inactive release history since December 2020, license mismatch, install scripts, and incomplete workflow audit warrant caution.
55%
Total Score
67
67
50
The package has had no registry release in over five years: its latest release was December 2020, with no releases in the last 12 months. This is a substantial maintenance concern despite the repository receiving a later push.
The artifact contains a license, but the manifest declares GPL-3.0-or-later while the license file was detected as LGPL-3.0. The mismatch creates legal uncertainty for consumers.
The package runs post-install and post-update Composer scripts, adding installation-time behavior that consumers must account for. No provided signal shows those scripts are unsafe, so this is a limited caution rather than a severe risk.
Only one registry account has publish access. The matching user-owned repository provides some continuity, but the narrow publishing base leaves limited visible redundancy if that maintainer becomes inactive.
There are three open pull requests and no issues or pull requests were merged in the last month. This suggests limited current development activity, though it is weaker evidence than a fully inactive repository.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.