The organization-backed repository, detailed README, and release notes provide useful continuity and transparency. Recent activity is thin, security scanning is absent, and all three workflow actions are unpinned, so pinning this version is preferable.
78%
Total Score
67
100
88
83
The package is 557 days old with nine releases and a short median interval, but only one release occurred in the last 12 months. The historical cadence is positive while recent release activity is a mild maintenance concern.
All recent commits come from one contributor, creating concentration risk. The organization-owned repository provides some ability to hand maintenance off, so this remains a caution rather than a severe risk.
Only one commit from one active maintainer was recorded in the last three months. This is thin recent activity, though the repository remains active rather than abandoned.
Composer build tooling is present, but no security-scanning tool was detected. For a small interface package this is a modest transparency and maintenance gap.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it does not by itself indicate abandonment or unsafe code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.