The organization-owned repository and release notes provide useful backing, while the package has no recorded commits in the last three months. Its license declaration is broader than the GPL-2.0 text detected in the repository, and no security policy is present.
64%
Total Score
75
63
50
The manifest declares GPL-2.0-or-later, while the repository license file was detected as GPL-2.0; the narrower detected license does not clearly cover the broader declaration.
The package is only 0 days old, with all 7 releases published on the same day; this shows active initial publishing but not an established maintenance record.
The repository recorded 0 commits and 0 active maintainers in the last three months, which is a meaningful maintenance warning despite the repository not being archived.
Composer build tooling is present, but no security scanning tool was detected; this is a modest transparency and maintenance gap for a dependency.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented; the organization-owned repository provides some compensating project backing.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.