The repository is small but has a complete consumer-facing package, tests, release notes, and a focused dependency set. Its single-owner maintenance model and missing security policy leave less resilience for future fixes.
62%
Total Score
50
100
90
50
Only one registry account has publish access. The organization-backed repository provides some context, but the observed publishing base remains narrow.
The package has 10 releases since 2017, but none in the last 12 months and the latest release was over two years ago, indicating reduced maintenance activity.
The repository recorded no commits and no active maintainers in the last three months; together with the old latest release, this raises abandonment risk.
No security policy is present in the linked repository, leaving vulnerability-reporting and response expectations undocumented.
The sole workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but both of its two action references are unpinned, reducing build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.