Usable with caveats: the package is licensed, tested, documented, and backed by a matching organization repository, but it has had no registry release for over two years and no commits in the last three months. Install-time scripts are absent and the repository uses security tooling, reducing operational risk despite the aging maintenance record.
64%
Total Score
75
90
67
The package has 10 releases over roughly five years with a median interval of about 43 days, but the latest release was over two years ago and there were no releases in the last 12 months. This materially lowers confidence in continued maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. Although it was pushed in November 2024, the current lack of recent development indicates slowed maintenance.
No security policy was found in the repository, leaving vulnerability-reporting guidance unclear. The presence of Dependabot and Psalm provides some compensation, but not a complete replacement for a documented reporting process.
All four workflows lack top-level token permission declarations, so their permissions are not explicitly minimized at workflow scope. No workflow requests top-level write access, which limits the severity of this hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pheature/toggle-core Version ^0.8 | — | — |
psr/event-dispatcher Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.