Clear documentation, a matching repository, and a small runtime dependency set reduce adoption friction. The young 0.1 release line, nearly four months without commits, and unpinned workflow actions leave meaningful maintenance and build-reproducibility concerns.
65%
Total Score
67
100
88
75
There were no commits and no active maintainers in the last three months, which is a meaningful warning for a package that is still in its 0.1 development line.
One issue and one pull request remain open, with no issues or pull requests closed in the last month; this modestly reinforces the signs of slowed activity.
Composer build tooling is present, but no security scanning tools were detected. This is a hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version 0.1.5 is not yet on a stable major version, so its API and compatibility expectations may still change despite it not being marked prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/polyfill-mbstring Version ^1.30 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.