The repository includes tests and a changelog, and organizational ownership provides some continuity. The declared proprietary license conflicts with the MIT license file, so licensing should be clarified before adoption.
48%
Total Score
50
100
75
83
This package has only one release, published nearly three years ago, with no releases in the last 12 months. That is a substantial abandonment concern for a dependency.
The repository recorded no commits and had no active maintainers in the last three months, reinforcing the lack of recent maintenance evidence.
The artifact contains an MIT license file, but the manifest declares the package proprietary. That mismatch creates avoidable uncertainty about the terms under which developers may use it.
The project uses Composer, but no security scanning tools were detected. This is a minor transparency gap rather than a decisive concern for package health.
The repository has no security policy. This limits disclosure transparency, though it is less significant than the package's inactive maintenance record.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.