Recent versioned release notes and a matching repository keep the package traceable. However, no commits in the last three months, one registry maintainer, and unpinned workflow actions reduce confidence in ongoing care.
67%
Total Score
50
100
86
67
The package has existed for about five years with 21 releases, but only one release in the last 12 months suggests a slower maintenance pace.
The repository recorded zero commits and zero active maintainers in the last three months, indicating limited recent development activity despite the recent release.
Composer is used for builds, but no security scanning tools were detected, leaving a modest repository hygiene gap.
The linked repository has no security policy, reducing transparency around vulnerability reporting and response expectations.
The single workflow was fully analyzed with no detected injection or high-severity findings, but all three action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
danielstjules/stringy Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.