Get informations about the current continuous integration environment
58%
Total Score
25
100
79
50
Only two releases were published, both in June and July 2020, with no release in roughly six years. This indicates very limited ongoing release maintenance, although the repository remains available and the package is stable rather than experimental.
There were no commits and no active maintainers in the three months measured. Combined with the old latest registry release, this is meaningful evidence of slowing maintenance.
The package and repository are both owned by the same individual account, so the source appears correctly aligned. Individual ownership also implies a relatively narrow maintenance base.
The repository uses Composer build tooling, but no security scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
No security policy was found in the repository, leaving vulnerability-reporting expectations unclear. This is a hygiene gap, but it is partly offset by the repository's continued availability and testing setup.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.