Usable with caveats: the package is licensed, documented, tested in its repository, and not deprecated or archived. However, the last release was over three years ago, there has been no recent commit activity, and publishing depends on one maintainer.
62%
Total Score
50
100
81
83
Only one account has registry publishing access. This indicates a narrow publishing base and increases continuity risk, though registry access alone does not measure the broader contributor community.
The package has 20 releases and a historically regular median interval of about 20 days, but its latest release was over three years ago and there were no releases in the last 12 months. This materially raises maintenance risk despite the earlier release record.
The repository recorded zero commits and zero active maintainers in the last three months. That is a meaningful sign of slowed maintenance, although it does not by itself show that the project is abandoned.
The repository has 12 stars, 7 forks, and 1 watcher, indicating a small user and contributor footprint. Popularity is only supporting evidence, but these counts provide little compensating evidence for the recent inactivity.
Composer is used as a build tool, but no security-scanning tools were detected. The established build tooling is positive, while the missing security scanning leaves a modest assurance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.