The README is thorough, the repository matches the package, and the code has one runtime dependency. A declared license and release notes help, but maintenance has stopped and no security policy is provided.
44%
Total Score
67
100
78
83
The package has had no release in about 4 years, despite nine releases overall. Its earlier monthly cadence shows prior maintenance, but does not offset the long current gap.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap and indicating little current maintenance capacity.
There were no new or closed issues or pull requests in the last month, with one issue still open. This adds modest evidence of inactivity but is weaker than the release and commit history.
The repository has 8 stars and 2 forks, indicating limited external adoption. Popularity is supporting evidence only, but it provides little additional confidence for a stale package.
Composer is used as a build tool, which fits the package ecosystem, but no security scanning tooling was detected. The tooling gap is a minor transparency concern rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
underpin/underpin Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.