The project has strong documentation, tests, licensing, and a recent release, but its maintenance record is uneven. Unpinned workflow actions, no security policy, and an install-time script add avoidable operational risk.
68%
Total Score
75
88
50
A post-install-cmd script runs during installation, which adds execution during dependency setup and deserves more scrutiny than a package with no lifecycle scripts.
The package has only three releases across 995 days, with a median interval of about 14 months, although two releases arrived in the last 12 months. This suggests modest maintenance capacity rather than abandonment.
There were no commits from active maintainers in the last three months. The recent release and repository push provide some compensation, but the lack of ongoing commit activity still raises maintenance risk.
The repository uses Composer build tooling, but no security-scanning tool was detected. For a dependency library, this is a modest transparency and maintenance gap.
No repository security policy was found, leaving vulnerability reporting and handling expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 || ^2.0 | — | — |
league/flysystem Version ^3.22 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.