The package is clearly identified, licensed, documented, and has a matching source repository. Its single-maintainer project has no recent commit activity, while the workflow uses three unpinned actions and lacks a security policy.
63%
Total Score
50
100
89
67
The package runs a post-install Composer lifecycle script, which adds install-time execution risk beyond a passive library and merits review before allowing automated installation.
The package and repository are owned by the same individual account, so the project has clear ownership but no observed organizational backing to compensate for its single-maintainer base.
There were no commits and no active maintainers in the last three months, despite the repository being less than two years old; this indicates maintenance has stalled after the recent release period.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a small project, but it provides no evidence of an active user or contributor community.
The repository has one star and no forks, providing little evidence of broad community adoption. Popularity is supporting evidence rather than a requirement, so this only modestly limits confidence in maturity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.