Usable with caveats: the package is clearly identified, licensed, stable, and backed by its matching organization repository. However, it has had no release in over a year and no commits in the last three months, with limited repository activity and no security policy.
68%
Total Score
67
100
88
88
The package has existed since 2019 but has only six releases, with no release in the last 12 months and a median interval of about 522 days. That slow cadence is a maintenance concern, although the latest release is still recent enough to avoid an abandonment verdict.
There were no commits and no active maintainers in the last three months, confirming that maintenance has currently stalled. The matching release and repository push on July 29, 2025 provide some compensating evidence, so this is caution rather than danger.
The repository has only one open issue and no issue or pull-request activity in the last month. This indicates a small, quiet project but not a severe support problem by itself.
Composer is used for the project build, but no security scanning tools are present. The missing scanning is a transparency gap, though the package is small and has no workflow automation to add further exposure.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.