The package is clearly licensed, documented, and tied to an organization-owned repository. Its small source footprint and stable release are positives, but maintenance has been inactive since April 2022 and the repository has no security scanning or policy.
58%
Total Score
100
72
75
Only two releases exist, with no release in more than four years and a median interval of about three years. This is strong evidence of limited ongoing maintenance, although the package may be mature and stable.
The repository has zero stars, forks, and watchers, providing no supporting evidence of adoption or community attention. This is a secondary concern rather than proof of poor quality.
Composer is used for builds, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance gap.
The repository is not archived, but its last push was in April 2022, so the unarchived status does not offset the evidence of inactivity.
The repository has no security policy, leaving no documented channel or process for handling vulnerability reports.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.