The package has had no commits or releases for about 14 months, and its only published version is 1.0. The repository is maintained under an organization, includes tests, documentation, a security policy, and an identified license, which reduces the risk of adopting an abandoned or opaque package.
63%
Total Score
67
79
100
One registry publishing account is a narrow release-management base, but the organization-owned repository provides meaningful backing that makes this less concerning.
This is the only release, published about 14 months ago, with no releases in the last 12 months. That limits evidence of ongoing maintenance and compatibility work.
There were no commits and no active maintainers in the last three months, which is a concrete sign that maintenance has currently stopped.
Composer build tooling is present, but no security scanning tooling was detected. The missing scanner is a hygiene gap, not evidence that the package is unsafe by itself.
The repository is not archived, although it was last pushed about 14 months ago, consistent with the lack of recent releases.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.