The package has a clear README, a license file, one runtime dependency, and documented release notes. It is not deprecated or archived, but its small public footprint limits confidence.
58%
Total Score
50
80
50
The package has 5 releases since October 2024, but none in the last 12 months; the latest release was over a year ago. This is a meaningful maintenance concern for a plugin that tracks external package downloads.
The repository had 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap. This weakens evidence of ongoing maintenance.
There are no open issues or pull requests and no recent issue or pull-request activity. That is compatible with a small stable utility, but provides little evidence of active support.
The repository has 3 stars, 1 fork, and 1 watcher, indicating a very small public user and contributor footprint. Popularity is only supporting evidence, but this limits confidence in external scrutiny.
The repository has no security policy. For a small Composer plugin that handles authenticated package downloads, this is a transparency gap, though it is not evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.