Usable with caveats: the package is mature, actively published, and backed by a maintained repository with tests and release notes. However, this release explicitly drops support for PHP 8.3, and recent commits come from one contributor, so verify your PHP version and be prepared for concentrated maintenance risk.
72%
Total Score
63
100
94
100
The repository is owned by the individual publisher rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.
All two recent commits came from one contributor, leaving maintenance highly concentrated and increasing continuity risk if that contributor becomes unavailable.
Only two commits were recorded in the last three months, indicating limited direct commit activity even though recent pull requests were merged.
The repository uses Composer and Phing for builds, but no security-scanning tools were detected. This is a transparency gap, though it is partly offset by the repository's other documented security controls.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.