It includes a matching Apache-2.0 license, a README, and no install-time scripts. The small repository has no security policy or scanning, so maintenance and security-review evidence is limited.
68%
Total Score
50
83
75
The package has eight releases over about three and a half years, with two releases in the last 12 months; the roughly eight-and-a-half-month median interval indicates a slow but not abandoned cadence. The release on the assessment date is compensating evidence.
The repository recorded zero commits and zero active maintainers in the last three months. Although the current release and push are recent, the lack of ongoing development evidence raises maintenance risk.
The repository has no stars or forks and only one watcher, so there is little external adoption evidence. Popularity is supporting evidence only, and the matching repository and recent release partly offset this weakness.
Composer is used as a build tool, which is appropriate for this package. No security scanning tools are configured, leaving a modest review gap rather than a severe dependency risk.
The repository has no security policy, so there is no documented channel or process for reporting vulnerabilities. This is a transparency and response-readiness gap, but not evidence of unsafe code by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.