The MIT license, release notes, and repository tests provide useful transparency. The absent security policy and unpinned workflow actions leave operational safeguards weaker than mature projects.
62%
Total Score
63
100
78
67
Only one account has registry publishing access, which is a limited publishing bus. The organization-owned repository provides some backing, so this is a minor concern rather than a severe risk.
The package has 25 releases over about 6 years, but it has had no releases in the last 12 months and the latest release was about 21 months ago. This is meaningful evidence of slowed maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with the absence of releases in the last year, this indicates currently inactive development.
There were no new or closed issues or pull requests in the last month, with two issues remaining open. This is a modest sign of low project activity rather than a severe abandonment indicator.
Composer is used for the build, but no security scanning tool was detected. The missing scanning automation is a hygiene gap, not evidence that the release is unsafe by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.