Tests, documentation, licensing, and minimal runtime dependencies provide a solid base. The repository lacks a security policy, and its two workflow actions are unpinned, leaving avoidable maintenance and build-integrity gaps.
58%
Total Score
0
100
71
67
There were no commits and no active maintainers in the last 3 months. This is direct evidence of currently inactive development and raises abandonment risk.
This is the only release, published about 2 years and 6 months ago, with no releases in the last 12 months. That makes ongoing maintenance uncertain for a package still at v0.0.1.
The repository uses Composer and Make, showing a basic build structure, but it has no security scanning tools. For a small library this is a moderate transparency gap rather than a severe defect.
The linked repository is not archived, so it remains available for maintenance. However, its last push was about 2 years and 6 months ago, which aligns with the stale release history.
The repository has no security policy. This leaves vulnerability reporting and response expectations unclear, although the package's small dependency surface limits the practical impact.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.