This is a usable but young package with a clear MIT license, stable v1.2 release, low runtime dependency surface, and a linked, non-archived repository that matches the package and references it in its README. However, maintenance capacity is thin: the package is only 118 days old, has three releases, and the repository recorded just one commit from one contributor in the last three months. The absence of tests, a changelog, security policy, and security scanning reduces transparency and operational confidence, while the pre-autoload-dump lifecycle script warrants review before adoption. Depend on it only after validating its build behavior and maintenance expectations for your project.
62%
Total Score
50
100
78
80
The package uses a pre-autoload-dump lifecycle script, adding install/build behavior that should be inspected because it can affect consumers during Composer operations.
A README is present and substantial, but neither the artifact nor repository contains tests or a changelog. For an SDK that dynamically builds protobuf code, the missing test coverage is a meaningful maintenance and regression risk.
The repository is owned by an individual GitHub user, with no organization backing shown. This provides no organizational maintenance redundancy to compensate for the concentrated contributor base.
The package is young at 118 days, with three releases and a median release interval of about 59 days. This demonstrates some release activity but provides limited evidence of long-term maintenance maturity.
All recent commit activity is concentrated in one contributor, with a top-contributor share of 100%. Because the repository owner is an individual rather than an organization, this creates a meaningful single-maintainer continuity risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.