This release appears usable and reasonably well-scaffolded, with a declared GPL-3.0-or-later license, README, tests, changelog, a non-archived repository, stable release status, and an organization-owned project. The main concerns are limited maturity—the package is only 78 days old with four releases—and very thin recent repository activity, with one commit from one contributor in the last three months. Security transparency is also incomplete: no security policy or security scanning was detected, and the sole workflow has top-level write permissions. These issues warrant caution for production adoption, but the active repository, organization backing, clean package structure, and absence of deprecation or dangerous workflow patterns keep it out of the unhealthy range.
72%
Total Score
63
100
83
80
The package is young at 78 days with four releases and a median interval of about 34 days; this shows some release activity but provides limited evidence of long-term maturity.
All recent commits came from one contributor, creating a concentrated maintenance path. Organization ownership partially compensates because maintenance can potentially be handed off, but no second active contributor is shown.
Only one commit was recorded in the last three months, from one active maintainer, indicating limited recent maintenance activity despite the repository's very recent push.
There are no open issues or pull requests and no issue or pull-request activity in the last month; this is neutral for a small organization-backed project but offers little evidence of community maintenance.
The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but these values provide no external adoption signal.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
moodle/moodle Version 4.5.* || 5.0.* || 5.1.* || 5.2.* | — | — |
composer/installers Version ~1.0 || ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.