Healthy and suitable to depend on, with some maintenance caveats. It has a long release history, a recent stable release, active recent commits, and strong repository transparency, but all recent work comes from one contributor and there is no security policy.
78%
Total Score
75
93
83
One contributor made all 81 commits in the last 3 months, creating a real continuity risk. The organization-owned repository provides some ability to hand maintenance off, but no second recent contributor is shown.
There are 22 open issues and no issues or pull requests were opened, closed, or merged in the last month, which is a maintenance responsiveness concern despite the strong recent commit activity.
Composer is used as a build tool, but no security scanning tools were detected. This is a modest supply-chain transparency gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. The repository otherwise shows active development and a clean workflow risk profile, which partially offsets but does not remove this transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 | — | — |
j4mie/paris Version ^1.5 | — | — |
ramsey/uuid Version ^4.2 | — | — |
povils/figlet Version ^0.1.0 | — | — |
voku/html-min Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.