MIT licensing, a focused dependency set, repository tests, and release notes support adoption. The absence of security scanning and fully unpinned workflow actions leave additional maintenance and build-integrity uncertainty.
46%
Total Score
0
100
63
100
The package has only two releases, with the latest published in February 2022 and none in the last 12 months; this is strong evidence of abandonment risk despite the short 12-day initial release interval.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the release history showing no updates for over four years.
The repository has 24 stars and one fork, providing limited supporting evidence of adoption but not enough to offset the prolonged absence of maintenance.
Composer build tooling is present, but no security-scanning tool was detected; that leaves a meaningful transparency gap for a package intended for application dependencies.
The repository is not archived, which preserves a path for future maintenance, but its last push was in July 2022 and does not offset the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.