This is a healthy, actively released package with a substantial history: 162 releases over about 5.6 years, 33 releases in the last 12 months, and a current stable version. It is not deprecated or archived, has clear GPL licensing, repository-backed documentation and tests, and no install-time lifecycle scripts. The main concerns are that all 14 recent commits came from one contributor, the repository has no security-scanning tooling or security policy, and the repository is very small with limited popularity; however, organization ownership, frequent releases, and an explicit repository/package match provide meaningful backing and reduce abandonment risk.
82%
Total Score
80
100
89
100
One contributor made 100% of the 14 commits in the last 3 months, creating a genuine single-maintainer continuity risk. Organization ownership provides some ability to hand off maintenance, but no second active contributor is shown.
There were no new or closed issues and no pull-request activity in the last month, while open pull requests are zero. This does not show a problem by itself, but it provides little evidence of an active external maintenance community.
The repository has only 1 star and no forks, indicating limited external adoption or review. Popularity is supporting evidence rather than a decisive health criterion, so this is a modest concern.
Composer is used as a build tool, but no security-scanning tools are reported. The missing scanning layer is a hygiene gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getpop/engine Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.