Clear documentation, tests, release notes, and licensing make the project easier to evaluate and maintain locally. Its last release and repository push were in November 2021, with no recent commits, while all three workflow actions are unpinned.
54%
Total Score
50
88
50
The package runs post-install and post-update Composer scripts. These add installation-time behavior that consumers should understand, although this signal alone does not show that the scripts are unsafe.
One registry maintainer is consistent with a small, user-owned project, but it provides little redundancy if that maintainer stops supporting the package.
The package has 25 releases, but its latest release was in November 2021 and it has had no releases in the last 12 months. The long period without a release is a meaningful maintenance concern.
There were no commits or active maintainers in the last three months, and the repository was last pushed in November 2021. The repository is not archived, but the prolonged inactivity raises abandonment risk.
The repository has no security policy, leaving consumers without a documented reporting path. This is a transparency gap, though it is less severe than the maintenance inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/cloud-spanner Version ^1.44.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.