The package is licensed, documented, and supported by repository tests, changelog tooling, and a recent release. Its single-maintainer setup, quiet recent commit activity, and workflow hygiene issues reduce confidence in sustained maintenance.
68%
Total Score
50
100
94
75
Only one registry account can publish the package, creating a limited publishing base; the linked repository is user-owned, so organizational backing does not offset that limitation.
The registry namespace and repository belong to the same individual account, and the repository is user-owned; this confirms ownership alignment but does not provide organization-level continuity.
The package has existed for about five years and released version 5.0.0 recently, but only one release occurred in the last 12 months, indicating a quiet cadence.
There were zero commits and zero active maintainers in the last three months, weakening evidence of ongoing maintenance even though a recent release and push are present.
The repository has no security policy, leaving vulnerability-reporting expectations and response guidance unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/http-message Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.