The package includes a clear README, tests, MIT licensing, and only one runtime dependency. Its security policy is present, but all three workflow actions are unpinned, so maintenance and build hygiene remain concerns.
58%
Total Score
33
100
75
100
Only two releases were published, with none in the last 12 months; the latest registry release was about 4 years ago. This is meaningful abandonment risk for a dependency.
There were no commits and no active maintainers in the last 3 months. Combined with the old last push, this supports a substantial maintenance concern.
The repository is owned by an individual rather than an organization, so the inactive commit record represents a thin maintenance base rather than organizational backing.
There are no open issues and one open pull request, but no issues or pull requests were closed or merged in the last month. This is consistent with limited current activity.
Composer build tooling is present, but no repository security scanning tools were detected. The security policy and tests provide some compensating transparency, but scanning coverage is still limited.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.