The documentation, tests, changelog, security policy, and active issue work provide useful project discipline. Its early history, single-contributor maintenance, and unpinned workflow actions leave meaningful adoption risk.
70%
Total Score
67
100
81
83
The package is only 1 day old and has 3 releases, with a median interval of about 12 hours. This shows active initial work but provides too little history to establish dependable maintenance.
One contributor made 100% of the 24 recent commits. Although the repository is organization-owned, no second active contributor is shown, so practical continuity remains fragile.
The repository has 24 commits in the last 3 months, but all activity comes from one active maintainer. The recent work is positive, while the concentrated maintenance base remains a risk.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and assurance gap, not evidence of abandonment.
Version v0.2.1 is not a stable major release, although it is not marked as a prerelease. The early version line warrants caution for production adoption.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.