The source repository is still active and organization-backed, but the package has not released in about four years. Workflow credential sharing and missing security scanning add maintenance risk, while the release remains licensed and has release notes.
55%
Total Score
75
67
67
The package has made no registry release in about four years despite 14 releases overall, which is a meaningful sign of stalled package maintenance.
The repository recorded no commits and no active maintainers in the last three months, although its recent push and non-archived status provide limited offsetting evidence.
The repository name does not match the package name and its README does not mention the package, creating some uncertainty about the package-to-source relationship; organization backing partly offsets that concern.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a transparency and maintenance-control gap.
The linked repository has no security policy, reducing clarity about vulnerability reporting and maintenance response.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.