The single-person ownership and absent security scanning leave less depth for long-term maintenance. Clear licensing, tests, release notes, a complete source tree, and a matching repository provide useful transparency.
64%
Total Score
50
100
81
83
Only one registry maintainer is listed, leaving limited visible publishing redundancy; the linked repository is also user-owned rather than organization-backed.
The package and repository both appear to be owned by an individual rather than an organization, providing no visible institutional maintenance backing.
The package has had five releases since April 2018, but none in over four years; that makes ongoing maintenance uncertain despite its established history.
There were no commits and no active maintainers in the last three months, indicating weak current development activity even though the repository remains available.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.