The package includes a clear README, tests, a matching LGPL license, and no install-time scripts. Maintenance has slowed, with no release in the last 12 months and no commits in the last 3 months; workflow references are also unpinned.
68%
Total Score
50
88
75
The repository is owned by an individual user rather than an organization, so the single registry maintainer is consistent with the project backing but leaves a relatively small visible ownership base.
The package has 25 releases over roughly 12 years, but none in the last 12 months. That recent release gap is a maintenance concern despite the long history and previously regular median interval of about 16 days.
There were zero commits and zero active maintainers in the last 3 months. Combined with no registry releases in the last 12 months, this indicates slowed maintenance and raises abandonment risk.
The repository uses Composer build tooling, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not evidence of unsafe code by itself.
The repository has no security policy. For a package that validates and sanitizes SEPA inputs, the missing disclosure process modestly reduces transparency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.