Its compact artifact is clearly licensed, tested in the repository, and has no install-time scripts. The organization-backed repository is not archived, but workflow dependencies are unpinned and no security policy is present.
64%
Total Score
75
100
81
67
The package has only 3 releases across about 9 years, with a median interval of about 4 years and no releases in the last 12 months. The latest release is recent enough to show continued publication, but the sparse cadence lowers maintenance confidence.
There were no commits and no active maintainers in the last 3 months. The repository was pushed in September 2025, but the recent inactivity still weakens confidence in ongoing maintenance.
The repository name does not match the package name and its README does not mention the package. This makes package-to-source ownership less transparent, even though the repository is dedicated to the corresponding class.
Composer build tooling is present, but no security scanning tooling was detected. For a small library this is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy. This limits disclosure transparency, although the package is small and has no other severe security signal here.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.