The project has a clear README, license, release notes, and organization backing. Its sparse release and commit history makes future fixes less certain, while the absence of a security policy leaves limited guidance for reporting issues.
63%
Total Score
75
88
50
Only 3 releases have appeared since December 2021, with a median interval of about 686 days and no release in the last 12 months. This indicates slow maintenance, despite the latest release being recent enough to show the project is not abandoned.
The repository recorded no commits and no active maintainers in the last 3 months. The push accompanying the latest release shows some recent activity, but not an ongoing maintenance cadence.
Composer build tooling is present, but no security-scanning tools were detected. For a stack configuration package, this is a modest hygiene gap rather than a severe dependency risk.
The repository has no security policy, so there is no documented process for reporting vulnerabilities. This is a transparency and response-readiness gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.