Tests, a substantial README, and release notes support practical use. The single-maintainer project has no security scanning or policy, and its workflow dependencies are not pinned.
64%
Total Score
50
100
81
75
One registry maintainer publishes the package. This is a limited publishing base, although the linked repository is also owned by the same individual, so the finding is a modest concern rather than a severe ownership gap.
The registry namespace and repository are owned by the same individual, and the repository owner is identified as a user rather than an organization. This is coherent ownership but provides limited organizational continuity.
The package has 12 releases since December 2019, but none in the last 12 months and the latest release was about 16 months ago, indicating a meaningful maintenance slowdown.
The repository recorded zero commits and zero active maintainers in the last three months. The recent push date is a compensating sign, but the current activity measure still points to limited ongoing development.
There are no open issues and one open pull request, with no issues or pull requests merged in the last month. The quiet issue tracker is not itself a serious concern, but it offers little evidence of active community maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ~5.4 | — | — |
symfony/console Version ~5.4 | — | — |
symfony/filesystem Version ~5.4 | — | — |
civicrm/composer-downloads-plugin Version ~3.0 | — | — |
lesser-evil/shell-verbosity-is-evil Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.