The repository has no commits in the past three months and no automated security scanning, which limits confidence in ongoing maintenance. The package is small, licensed, non-deprecated, and has a current stable release, but its seven releases were heavily clustered rather than showing a steady cadence.
58%
Total Score
50
100
88
67
The repository is owned by an individual account rather than an organization, so the single registry maintainer is consistent with the available project backing but leaves a thin ownership base.
Seven releases across 736 days, with only two in the last 12 months, suggests a small or intermittent maintenance pattern; the latest release is recent, which partly offsets the concern. Releases were clustered within minutes rather than following a steady cadence.
There were zero commits and zero active maintainers in the past three months, a meaningful sign of limited ongoing maintenance capacity.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, reducing clarity about vulnerability reporting and maintenance response.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.