The package is documented and tested, with a small runtime dependency surface. Its registry release history is sparse, while the organization-owned repository has only one recent active contributor and lacks a security policy.
74%
Total Score
67
100
94
83
Only two releases exist, with no releases in the last 12 months and a median interval of about 376 days. This is a meaningful maintenance-cadence concern, though recent repository activity provides some compensation.
All recent commits came from one contributor. Organization backing reduces the risk compared with an unaffiliated project, but no second recently active contributor is shown.
There was one commit in the last three months from one active maintainer. Recent activity is positive, but the very low volume limits confidence in sustained maintenance.
No repository security policy was found. This is a transparency gap, though it is less significant for a small Composer plugin than for a security-sensitive library.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.