Healthy and suitable to use, with a small maintenance caveat. It has a long release history, a recent release and repository update, clear licensing, and organization backing; recent work is concentrated in one contributor and the repository has no security policy.
78%
Total Score
83
100
89
90
All recent commit activity comes from one contributor, creating a real continuity risk. Organization ownership provides some capacity to hand maintenance to others, so this is a caution rather than a severe risk.
The repository has only 1 star and 1 fork, indicating limited community visibility. This is supporting evidence only and is outweighed by the active, organization-backed source and recent release.
The repository uses Composer for its build or package workflow, but no security scanning tools are reported. For this small Composer plugin, the missing scanning is a transparency gap rather than evidence of unsafe behavior.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the package is small and has no reported workflow activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.