Healthy and actively maintained, with clear licensing, frequent releases, repository tests, and strong build hygiene. The main caveat is that nearly all recent commits come from one contributor and the project has little public adoption.
78%
Total Score
70
100
94
90
Only one registry account has publish access. That is a genuine continuity concern for a user-owned project, although repository activity shows a second active contributor and does not indicate abandonment.
The registry namespace and repository owner match, but both belong to a user rather than an organization. This supports package identity while offering less institutional maintenance backing.
One contributor made 22 of 23 commits in the last three months, leaving maintenance highly concentrated. A second contributor remains active, but the concentration still creates continuity risk.
The repository has 1 star, 0 forks, and 0 watchers. This is limited adoption evidence, but popularity is supporting evidence and the package's active release and commit history compensates for it.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the active tooling and workflow controls provide some compensating evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
yiisoft/data Version ^2.0 | — | — |
psr/http-client Version ^1.0 | — | — |
symfony/console Version ^7.2 | — | — |
psr/http-factory Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.