Its documentation, tests, and clear project ownership make the package easier to adopt. The long release pause, inactive recent commits, tiny public footprint, and absent security policy leave maintenance and oversight concerns.
58%
Total Score
75
50
83
83
The package declares 10 runtime dependencies, creating meaningful coupling for a foundational ERP module. This is a maintenance consideration, but the profile does not by itself indicate that adoption is unsafe.
The package has 301 releases since August 2022, but its latest release was over a year ago and there were no releases in the last 12 months. The long history helps, but the recent pause lowers confidence in ongoing maintenance.
There were no commits and no active maintainers in the last 3 months. This is the clearest maintenance concern, although the repository is not archived and the release history is substantial.
There is one open issue and no issue or pull-request activity in the last month, offering little evidence of active community support.
The repository has only 1 star, 1 fork, and 1 watcher, indicating a very small public footprint. Popularity is supporting evidence rather than a verdict, but this provides little external validation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^4.0 | — | — |
guava/calendar Version ^1.2 | — | — |
coolsam/modules Version ^4 | — | — |
filament/filament Version ^3.2 | — | — |
wildside/userstamps Version ^2.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.