Its small footprint, absent security policy, and lack of automated security scanning reduce confidence in long-term support. The package is clearly documented enough to install, with a matching repository and a release for this version.
58%
Total Score
0
58
50
The latest release was about four years ago, with no releases in the last 12 months. This is strong evidence of stagnation for a package intended as a maintained dependency.
The repository had zero commits and zero active maintainers in the last three months, reinforcing that current maintenance has stopped rather than merely slowed.
The package declares no license, contains no license file, and the repository has no license file. That creates a real legal and transparency gap for adoption.
The repository has one star and no forks, providing little evidence of broad community review or adoption. This is supporting caution rather than a verdict on its own.
Composer is used for the build, which is appropriate, but no security-scanning tooling was detected. The missing scanning reduces maintenance assurance for a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pierreminiggio/github-user-agent Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.