The small dependency set and clear README make integration straightforward. The project has no security policy or security scanning, so maintenance and oversight deserve extra scrutiny.
58%
Total Score
50
100
79
50
Only two releases have appeared since May 2021, with no release in nearly five years. The release notes for this version provide some transparency, but the long inactivity raises abandonment risk.
The repository recorded no commits and no active maintainers in the past three months, consistent with the long release gap. The repository is not archived, which is a limited compensating signal.
The repository has zero stars and forks and one watcher, providing little community evidence to offset the inactive release and commit history. Popularity is supporting evidence only, so this remains a secondary concern.
The repository uses Composer for its build and package workflow, but no security scanning tools were detected. The build setup is clear, while security oversight is limited.
No repository security policy was found. This is a transparency gap for reporting vulnerabilities, though it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
underpin/underpin Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.