Healthy and suitable to use, with a small maintenance caveat. The repository is active, licensed, documented, and backed by an organization, but releases are infrequent and all recent commits come from one contributor.
79%
Total Score
75
100
88
90
The package has existed for about 5 years 6 months and made one release in the last 12 months, but its median release interval is about 2 years 4 months, indicating a slow cadence.
All 5 recent commits came from one contributor, leaving a thin active maintainer base. Organization backing provides some handoff capacity, but no second active contributor is shown.
There is one open issue but no issue or pull-request activity in the last month; this is a minor transparency concern, not evidence of abandonment by itself.
Composer is used for builds, but no security scanning tools are configured, leaving a modest supply-chain hygiene gap.
All 5 workflows omit top-level token permissions, so their effective permissions are not explicitly minimized in the workflow definitions. None declares top-level write access, limiting the concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
msp/devtools Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.