The README, license, and matching organization-owned repository make the package easy to identify and understand. Maintenance is unproven: it has had no commits for about four months, only one release, no tests, and no security policy.
62%
Total Score
83
100
78
75
The package includes a substantial README, which supports consumer understanding. Missing tests and a changelog are expected to be judged primarily in the repository, and neither is present there; for this global Composer plugin, the absence of tests is a meaningful maintenance gap.
The package is about four months old and has only one release, so there is little release history from which to judge ongoing maintenance.
There were zero commits and zero active maintainers in the last three months. For a newly published plugin with only one release, this leaves ongoing maintenance capacity unproven.
Composer is used as the build tool, but no security scanning tooling is present. The missing scanning is a modest transparency and hygiene gap rather than evidence that the package is unsafe.
The linked repository is not archived, but its last push was about four months before collection, consistent with the observed maintenance slowdown.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.