The stable major version, small dependency surface, tests, and release notes support adoption. Maintenance is quiet, and the repository lacks a security policy while its only workflow uses an unpinned action.
64%
Total Score
75
100
88
50
The package has 18 releases over roughly 10 years, but its latest registry release was about 3 years and 7 months ago and there were no releases in the last 12 months. That is a meaningful freshness concern for a dependency.
There were no commits and no active maintainers in the last 3 months. The recent repository push provides some contrary evidence, but current development activity is still limited.
The repository uses Composer build tooling, but no security scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.
The single workflow has no untrusted trigger or audit finding, but its one action reference is unpinned. That weakens build reproducibility and supply-chain hygiene without being a severe risk on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.