The source is actively updated and includes tests, release notes, and security tooling. One contributor handles all recent commits, and the package-level deprecation makes long-term continuity uncertain.
58%
Total Score
88
75
75
Packagist marks the entire package as abandoned, although the listed replacement is the same package and the repository shows recent activity. This remains a material continuity warning.
All 10 recent commits came from one contributor, leaving maintenance highly dependent on a single person. Organization backing provides some handoff capacity but does not remove the concentration risk.
The repository name does not match the package name and its README does not mention this package, so the linkage is less transparent and may indicate a package-to-repository mismatch.
No repository security policy was found, which is a modest transparency gap for reporting vulnerabilities.
Version 0.22 is not a prerelease, but it remains below major version 1, which indicates some API maturity uncertainty despite stable release status.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.