The repository has had no commits or active maintainers for about four months, and its two releases arrived within minutes of each other. Tests, documentation, licensing, and package ownership are otherwise clear, but workflow references are unpinned and no security policy is provided.
58%
Total Score
50
100
83
83
There were zero commits and zero active maintainers in the last three months, consistent with no repository push for about four months. For a newly released plugin, this is a meaningful abandonment risk.
The package is about 127 days old, but both releases were published within minutes on the same day and there have been no later releases. This indicates limited demonstrated maintenance rather than a mature release history.
There were no new or closed issues or pull requests in the last month, and none are currently open. This provides no evidence of ongoing maintenance or user support.
The repository has zero stars, forks, and watchers. Low popularity is supporting evidence of limited adoption, but it is not decisive for a small package by itself.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a modest repository hygiene gap rather than evidence that the package cannot be built.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
vimeo/psalm Version ^5.15 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.