The package is small and clearly licensed, with a focused dependency set and organization backing. The published release notes document a concrete fix, but the project offers little additional operational evidence.
62%
Total Score
75
100
79
75
The package is young, with four releases in about ten months and a median interval of about five days; its latest release was about four and a half months ago. This shows initial activity but leaves a limited maintenance record.
The repository recorded zero commits and zero active maintainers during the last three months. This materially limits evidence of ongoing maintenance, even though a recent release exists.
Composer is used as the build tool, but no security-scanning tool was detected. The missing scanner is a hygiene gap, not evidence that the release is unsafe.
The repository has no security policy. For a small Composer plugin this is a transparency gap, although it does not by itself indicate abandonment.
Version 0.2.2 is not marked as a prerelease, but the package has not reached a stable major version. That is a modest maturity concern rather than a severe adoption blocker.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.