The clear README, tests, release notes, and matching source repository improve adoption confidence. The package is licensed, stable, and has no install-time scripts, though its limited security-process evidence leaves less transparency than mature projects.
70%
Total Score
50
88
75
The registry namespace and repository are owned by the same individual account, showing ownership alignment but no organizational backing to compensate for a concentrated maintainer base.
Only two releases have been published since December 2022, with a median interval of about 2 years and 10 months. A release appeared within the last 12 months, which partly offsets the sparse history.
All recent commits came from one contributor, leaving maintenance dependent on a single person. The repository is user-owned rather than organization-owned, so there is no shown organizational handoff buffer.
There was one commit in the last three months from one active maintainer. Recent activity is positive, but the low volume provides only modest evidence of sustained maintenance.
The project uses Composer and Robo build tooling, but no security-scanning tools were detected. The tooling is a positive maturity signal, while the missing scanning coverage is a modest hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/console Version ^7.0 | — | — |
sweetchuck/junit-merger Version 2.x-dev | — | — |
symfony/dependency-injection Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.