The package is MIT-licensed, has a README and release notes, and uses Composer plus security scanning. Its repository does not clearly identify the package, and only one maintainer is publishing it.
57%
Total Score
50
86
75
Only one registry account has publishing access, and the repository is backed by a user rather than an organization. This creates a thin publishing base, although it is not by itself evidence of abandonment.
There have been no releases in the last 12 months, despite ten releases overall and a recent release at the start of the observed history. This lowers confidence that maintenance is continuing.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the lack of releases in the last year, this is a meaningful maintenance concern.
The repository name does not match the package name and its README does not mention the package, so the link does not clearly establish that this repository belongs to the published package.
The linked repository has no security policy, reducing transparency about how vulnerabilities should be reported. The repository does use GitGuardian, which partly compensates for this gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.