Release notes, repository tests, and recent work provide useful maintenance evidence. MIT licensing, a small dependency set, and organization ownership help, but the alpha status limits confidence.
65%
Total Score
83
86
50
The package has six releases since February 2021, with only two in the last 12 months and a median interval of about 323 days. This indicates a slow release cadence rather than abandonment, so it is a modest maintenance concern.
One contributor made all 11 commits in the last three months. Organization ownership provides some handoff capacity, but no second recently active contributor is shown, leaving maintenance continuity exposed.
The repository has no documented security policy. This is a transparency gap for reporting vulnerabilities, though the available Psalm scanning provides some compensating security practice.
The assessed version is a prerelease, and all recent releases are prereleases. That signals an immature API and higher change risk for consumers.
The single workflow was fully analyzed with no audit findings, dangerous triggers, untrusted checkouts, or script injection. Both action references are unpinned, so their contents can change unexpectedly and create a modest supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
dhii/collections-interface Version ^0.5.0-beta1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.