Healthy enough to use, with caveats. Recent maintenance and five active contributors support the release, but its long release intervals, absent tests, and limited security-policy hygiene leave some maintenance risk.
76%
Total Score
100
100
81
80
The artifact has a README and changelog, and the repository has a changelog and GitHub Releases. Neither the artifact nor repository contains tests, which is a modest transparency and maintenance gap for a library module.
The package has existed for over 7 years but only has 3 releases, with a median interval of about 3 years 9 months; a release yesterday and one in the last 12 months provide some current-activity compensation.
Composer build tooling is present, but no security-scanning tool was detected; the build setup is adequate while automated security coverage is limited.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The only workflow lacks top-level token permissions. No write permissions were detected, but explicit least-privilege configuration would provide stronger CI hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.