Recent releases and a matching repository with a clear README provide useful continuity. The project has one registry maintainer, no security policy, and all three workflow actions are unpinned, so oversight and build reproducibility are limited.
78%
Total Score
50
100
89
75
Only one account has registry publish access. The matching repository and recent releases provide some compensation, but a single publisher leaves limited visible succession capacity.
The package and repository are owned by the same individual account, so the source location is coherent, but there is no organization backing to broaden maintenance capacity.
The repository recorded no commits and no active maintainers in the last 3 months. Recent releases partly offset this, but the current development activity is thin.
The repository has 7 stars, 0 forks, and 1 watcher. This indicates a small user and contributor footprint, though popularity is supporting evidence rather than a health verdict.
Composer build tooling is present, but no security-scanning tool was detected. The absence of scanning is a modest transparency and maintenance gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.11 || ^2.1 | — | — |
laminas/laminas-filter Version ^3.2 | — | — |
samsonasik/array-lookup Version ^1.8 || ^2.2 | — | — |
laminas/laminas-validator Version ^3.8 | — | — |
symfony/polyfill-mbstring Version ^1.33 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.