Tests, release notes, and a matching organization-owned repository provide useful transparency. Recent repository activity is absent, and no security policy or scanning is reported; pin this version and verify ongoing support.
62%
Total Score
75
79
50
The package has 8 releases since 2019, but none in the last 12 months and the latest registry release was about two years ago. This is meaningful maintenance risk despite a previously regular median interval of about 119 days.
There were no commits and no active maintainers in the last three months. The recent repository push is some compensating evidence, but the current development silence still raises maintenance risk.
Composer build tooling is present, but no security-scanning tools were detected. The build setup is appropriate for the package, while the missing scanning capability is a modest hygiene concern.
The repository has no security policy, leaving vulnerability-reporting and response expectations unclear. This is a transparency gap, although it is not evidence of a security incident.
Version 0.9.3 is not marked as a prerelease, but the package remains below 1.0, which indicates less maturity than a stable major release. The absence of recent prereleases does not offset the pre-1.0 status.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.