The package has clear documentation and a matching organization-owned repository. Its very young release history and no recent commits make long-term maintenance uncertain. Workflow dependencies are also unpinned.
62%
Total Score
50
100
78
75
The repository had zero commits and zero active maintainers during the last three months, a meaningful sign that development may have stalled despite the repository not being archived.
The package is only 155 days old and all five releases were published within a very short burst, so there is little evidence of sustained maintenance.
There are no open issues or pull requests and no recent issue activity. This does not prove abandonment, but it provides no evidence of an active user or contributor community.
The repository has one star and no forks or watchers. This is weak supporting evidence, but popularity alone does not determine health for a young package.
Composer is used as a build tool, but no security scanning tool was detected. The missing scanning is a modest repository-hygiene gap rather than a direct dependency risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.