This release appears healthy and suitable for dependency use: it is a stable, non-deprecated package with a strong release cadence, an active non-archived organization-backed repository, multiple recent contributors, tests, documentation, and clear MIT licensing. The main reservations are operational rather than abandonment concerns: the repository lacks a published security policy, its workflow grants top-level write permissions, and no security-scanning tooling was detected. Low repository popularity and the absence of a changelog modestly reduce transparency but are outweighed by recent releases, GitHub Releases, repository tests, and ongoing commit activity.
84%
Total Score
100
100
89
80
The repository has only 5 stars, 4 forks, and 3 watchers, which limits external validation and community visibility, though popularity is supporting evidence rather than a health verdict.
Composer build tooling is present, but no security-scanning tools were detected. This leaves a moderate process gap, although the package still has structured build support.
No repository security policy was found, reducing transparency for vulnerability reporting and coordinated disclosure.
The analyzed workflow declares top-level write permissions, which grants broader CI token authority than a read-only default and increases workflow-impact risk if compromised.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
amphp/amp Version ^3.0 | — | — |
ramsey/uuid Version ^4.7 | — | — |
google/protobuf Version ^3.25 | — | — |
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.