The package has only a 92-character README, no repository tests, and no security-scanning tooling, leaving maintenance and integration practices poorly documented. Its Apache-2.0 declaration and non-deprecated, non-archived status provide some reassurance, but not enough to offset its age.
42%
Total Score
25
71
50
The latest release was published in January 2020, with no releases in the last 12 months despite the package being over seven years old. This is strong evidence of abandonment risk, though the package is not formally deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, matching the long release gap. This substantially weakens confidence in ongoing maintenance.
The artifact includes a README, but it is only 92 characters and provides little usage guidance; the absence of tests and a changelog is normal for published artifacts and is not penalized.
There were no new or closed issues or pull requests in the last month, and no open work is visible. This supports the conclusion that the project is inactive rather than actively stable.
The repository uses Composer, but no security-scanning tools were detected. For a runtime extension integration package, that is a meaningful maintenance and transparency gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.