The package is clearly licensed, documented, and backed by an organization whose repository matches the package. Its small release history and no commits in the last three months make long-term maintenance less certain.
64%
Total Score
75
83
50
Only three releases have been published since December 2022, with a median interval of about 591 days and one release in the last 12 months; this indicates a slow maintenance cadence.
The repository recorded no commits and no active maintainers in the last three months. The recent release shows some activity, but the short-term development gap lowers maintenance confidence.
The linked repository has no security policy. This is a transparency and response-process gap, though it is not evidence that the package is unsafe.
The assessed release is v2.0.0-alpha1, and two-thirds of recent releases are prereleases, so the API and behavior may still change.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
micro/kernel Version ^2.0 | — | — |
php-ffmpeg/php-ffmpeg Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.