The MIT license, detailed README, release notes, and repository tests improve transparency, while recent commits show some activity. The workflow uses five unpinned actions and has no security policy, adding operational hygiene concerns.
18%
Total Score
67
100
69
67
Packagist marks the entire package as abandoned, with no replacement specified; this is a direct warning against taking a new dependency on it.
The linked repository is archived, so the project is no longer intended for ongoing maintenance even though it was pushed recently.
The repository is owned by an individual rather than an organization, so there is no visible organizational maintenance capacity to offset concentrated contribution activity.
Two contributors were active, but one made about 85% of recent commits, leaving maintenance concentrated if the primary contributor stops.
Composer build tooling is present, but no security scanning tools were detected; this is a modest verification gap rather than evidence of abandonment by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.