The repository has organization backing, a matching source tree, and release notes for this version. Its license declaration does not exactly match the detected repository license, and no security policy is published.
68%
Total Score
67
100
88
75
The package declares GPL-2.0-or-later, while the repository license was detected as GPL-2.0. The release is licensed, but the mismatch creates a transparency concern.
The repository recorded zero commits and zero active maintainers in the last three months. That is a meaningful recent-maintenance gap, partly offset by the repository having been pushed more recently than that window.
Five pull requests are open, while no issues or pull requests were merged in the last month. This suggests unresolved maintenance work, though it is not evidence of abandonment by itself.
Composer is used as a build tool, but no security-scanning tools are configured. The missing scanning is a hygiene gap rather than a direct dependency failure.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for consumers.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.