The library is documented, licensed, and has a clear source tree. Its organization-backed project has no recent activity and no security scanning, so future fixes are uncertain.
55%
Total Score
75
80
50
The latest release was published in April 2022, and there were no releases in the following 12 months. This indicates a long maintenance gap, though the package has six releases and a stable major version.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. This materially raises the risk that compatibility or security fixes will not arrive promptly.
Composer is used for the build, but no security scanning tools were detected. The build setup is present, while automated security coverage is limited.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency and maintenance weakness, though it is not evidence of a vulnerability by itself.
The single workflow was fully analyzed with no audit findings or untrusted triggers, but all three action references are unpinned. The workflow also lacks a top-level permissions block, which is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0||^2.0||^3.0 | — | — |
slick/event Version 1.1.x-dev | — | — |
psr/http-message Version ^1.0||^2.0||^3.0 | — | — |
psr/event-dispatcher Version ^1.0||^2.0||^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.