Clear licensing, tests, release notes, and a matching repository support adoption. Maintenance has gone quiet, with no commits or issue activity recently, while the workflow uses two unpinned actions and has no security policy.
62%
Total Score
67
100
88
75
Only two releases are recorded, with no releases in the last 12 months and the latest release about 16 months ago. This indicates a small and inactive release history, though the repository was pushed more recently.
The repository recorded zero commits and zero active maintainers in the last three months. That is a meaningful maintenance warning for a package consumers may need to rely on over time.
There are open issues and pull requests, but none were opened, closed, or merged during the measured month. This supports the broader concern about limited recent activity.
Composer is used for builds, but no security scanning tool was detected. The missing scanner is a modest transparency and hygiene gap, not evidence of unsafe code.
No security policy was found in the repository. This weakens the project's published process for handling vulnerabilities, although it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.