The README and changelog make the small codebase understandable, and its dependencies are limited. Missing security policy and scanning reduce confidence for a client handling cluster access.
58%
Total Score
50
100
86
83
Only one account has registry publishing access. That can be sufficient for a small package, but it leaves limited visible redundancy if maintenance stops.
The package has had no releases in the last 12 months, and its latest release was about 18 months ago. Its 17 releases over roughly seven years show prior activity but do not offset the current pause.
The repository recorded no commits and no active maintainers in the last three months. The repository is not archived, but current development activity is absent.
Composer is used for the build, but no security scanning tools were detected. The package remains buildable, while the missing automated security checks reduce maintenance assurance.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap for a client that communicates with Kubernetes APIs.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.3|^7.0 | — | — |
softcreatr/jsonpath Version ^0.8.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.