Usable with caveats: the package is licensed, documented, stable, and backed by an organization, but its latest registry release was about 22 months ago and recent repository activity is absent. The linked repository also does not clearly identify this package, which increases adoption risk.
57%
Total Score
75
100
78
88
There have been four releases since December 2021, but none in the last 12 months and the latest release was about 22 months ago. This materially raises maintenance and abandonment concerns.
The repository had zero commits and zero active maintainers in the last 3 months. Together with the long release gap, this is a meaningful sign of currently inactive maintenance.
The repository name does not match the full package name and its README does not mention the package, leaving uncertainty about whether the linked repository directly backs this release. Organization backing reduces, but does not remove, that concern.
The repository has only 2 stars, 2 forks, and 3 watchers. This offers little community validation, but low popularity alone is not a health verdict for a small specialized extension.
Composer is used for builds, showing basic project tooling, but no security scanning tools are present. This is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.