This release appears usable and actively maintained: it has 13 releases over 166 days, including a recent stable v1.0.2, an unarchived repository pushed very recently, repository tests and changelog coverage, and no install-time lifecycle scripts or dangerous workflow patterns. The main concerns are concentrated ownership and maintenance risk—one user maintains the package and accounts for all recent commits—along with limited adoption, no repository security scanning or security policy, and incomplete GitHub Actions token-permission declarations. These issues warrant review before adopting it for a critical dependency, but the recent release and repository activity keep it in the caution rather than unhealthy range.
72%
Total Score
63
100
83
75
The repository owner is a GitHub user rather than an organization, so the package does not show organization-level backing that could mitigate its single-maintainer concentration.
One contributor made all six commits in the last three months, giving the project a bus factor of one and creating a genuine continuity risk. The repository is user-owned rather than organization-owned, so there is no provided project-backing evidence to offset this concentration.
There is only one open issue, with one new issue and no closures in the last month. This is limited evidence of issue-management capacity, but not by itself a severe maintenance signal.
The repository has three stars, zero forks, and one watcher, indicating limited external adoption or validation. Popularity is supporting evidence rather than a verdict, so this lowers confidence in maturity without making the package unfit.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning coverage is a hygiene gap for a package intended to be consumed as a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0 | — | — |
wamania/php-stemmer Version 4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.