It is a small, focused Composer plugin with one runtime dependency, a matching repository, and a clear README. The license wording differs from the detected file, and no recent maintenance or security policy reduces confidence in relying on it.
42%
Total Score
0
100
70
75
The latest release was published in July 2022, and there were no releases in the following 12 months. This long release gap is a substantial abandonment concern for a dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package having been inactive since July 2022.
The package declares GPL-2.0+ and includes a license file detected as GPL-2.0. The discrepancy warrants checking the intended licensing terms, although the release is not unlicensed.
The linked repository has no security policy. For a small package this is a transparency gap, though it is less significant than the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.