This release appears usable but warrants caution before becoming a critical dependency. It has a declared GPL-3.0-or-later license, complete README/tests/changelog scaffolding, a substantial 515-file tree, stable non-prerelease versioning, no registry deprecation, and an unarchived organization-owned repository that was pushed very recently. However, the package is young at 78 days, repository activity over the last 3 months consists of only one commit from one contributor, and the repository has no security policy or security scanning while its update workflow has top-level write permissions. The organization backing partly mitigates the concentrated bus factor, but the limited observed maintenance history and security-hygiene gaps make this a moderate-risk dependency rather than a clearly mature one.
68%
Total Score
63
100
83
80
The package is only 78 days old with four releases and a median interval of about 34 days, providing some release continuity but limited evidence of long-term maintenance maturity.
All three-month commit activity is concentrated in one contributor, which is a maintenance risk; the organization-owned repository partly compensates because maintenance can potentially be handed off internally.
Only one commit was made in the last 3 months by one active maintainer, indicating limited observed maintenance activity despite the very recent push.
There are no open issues or pull requests and no issue or pull-request activity in the last month; this is ambiguous because it may reflect a quiet project rather than abandonment, so it is only a modest concern.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but popularity alone is not decisive for an organization-owned package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
moodle/moodle Version 4.5.* || 5.0.* || 5.1.* || 5.2.* | — | — |
composer/installers Version ~1.0 || ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.