The repository is correctly linked and organization-backed, with a clear license and no install-time scripts. Its small footprint, absent security scanning, and minimal project documentation provide limited evidence of sustained care.
46%
Total Score
50
67
83
This is the package's only release, published in August 2023, with no releases in the following three years. That strongly increases abandonment risk, although the stable version and organization-backed repository provide limited context.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long release gap. The repository is not archived, but there is no observed recent maintenance.
The artifact has no README, tests, or changelog, while the repository does contain a README and uses GitHub Releases. Missing tests and changelog in a published artifact are expected; the package-level documentation gap is a minor transparency concern.
There has been no issue or pull request activity in the last month, and one issue remains open. This adds modest concern when combined with the absent recent commits.
Composer is used as a build tool, which supports reproducible project structure, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.