The package has a clear README, tests, Apache-2.0 licensing, and an organization-backed repository. Its workflow uses floating container images, while no recent commits or releases reduce confidence in ongoing care.
63%
Total Score
67
100
89
75
The latest release was about 2 years and 5 months ago, with no releases in the last 12 months. Sixteen releases show prior activity, but the prolonged pause raises maintenance concern.
There were no commits and no active maintainers in the last 3 months. Combined with the absence of releases in the last year, this points to inactive current maintenance.
There is only one open issue and one open pull request, with no new or closed activity in the last month; this is limited evidence of current project engagement.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. The established build setup helps, while the missing scanning is a modest hygiene gap.
No security policy was found. This weakens vulnerability-reporting transparency, although the package's tests, licensing, and organization-backed repository provide some compensating maturity evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.