Repository tests, release notes, and organization backing provide useful support. The license mismatch, install-time scripts, absent security policy, and unpinned workflow actions add transparency and maintenance concerns.
43%
Total Score
50
75
50
The last release was over four years ago, with no releases in the past 12 months. That is strong evidence of abandonment risk for a package developers may need to maintain.
The repository recorded zero commits and zero active maintainers in the past three months, reinforcing the long release gap and leaving little evidence of ongoing maintenance.
The manifest declares GPL-2.0+, while the repository license file was detected as GPL-3.0. The package is licensed, but the mismatch creates avoidable legal uncertainty.
The package runs post-install and post-update Composer scripts. These are not automatically unsafe, but they increase the actions performed during dependency installation and updates.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented. This is a transparency gap, though it does not prove that security issues are unmanaged.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.