Documentation and licensing are in place, and installation does not run lifecycle scripts. Maintenance is concentrated in one contributor, but the organization-backed repository remains active and this release includes release notes.
76%
Total Score
70
88
75
Only one registry account has publishing access, which is a limited publishing base. The organization-backed repository provides some compensation for that concentration.
All two recent commits came from one contributor, creating a meaningful single-contributor risk. Organization ownership partly reduces handoff risk but does not remove the concentration.
There is only one open issue and no recent issue or pull-request activity. This is a small transparency gap, but it is not strong evidence of abandonment alongside the recent release and commits.
Composer is used for builds, but no security-scanning tooling was detected. The missing scanning is a hygiene gap rather than evidence that the release is unsafe or abandoned.
The repository has no security policy. This reduces vulnerability-reporting transparency, though it is not by itself evidence of poor maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.