Healthy and reasonable to use, with one important maintenance caveat: the project is actively releasing and well documented, but all recent commits come from one contributor. Review future maintenance before making it a deeply embedded dependency.
82%
Total Score
67
100
94
90
The repository is owned by the same individual as the registry namespace, providing clear ownership, but it is user-backed rather than organization-backed and therefore offers limited maintenance redundancy.
One contributor made all nine commits in the last three months, creating a real continuity risk for a user-owned project with no organizational backing.
Composer build tooling is present, but no security scanning tools were detected; the strong test and CI evidence partly compensates for this transparency gap.
The CI workflow lacks top-level token permissions and relies on job-level permissions, which is less explicit than a repository-wide read-only declaration but does not show any write permissions.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.