Usable with caveats: the package is established, recently released, licensed, and backed by a matching organization repository with tests. Maintenance is thin, with one commit from one contributor in the last three months, and no security policy or scanning is present.
73%
Total Score
67
100
89
88
All recent commits came from one contributor. Organization ownership provides some handoff potential, but no second active contributor is shown in this period.
Only one commit was recorded in the last three months from one active maintainer, indicating limited recent maintenance capacity despite the recent release.
The repository has one star and no forks, showing limited external adoption. This is only supporting evidence and does not outweigh the package's release history, repository match, and organization backing.
Composer is used for builds, but no security scanning tool is configured, leaving a transparency and monitoring gap.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
wedeto/util Version ^1.1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.