Usable with caveats: it has a long release history, a current stable release, clear licensing, and matching organization-backed source code. Recent repository activity is quiet, with no commits in three months and no security policy, so verify maintenance before making it a core dependency.
72%
Total Score
75
100
88
75
A README is present, although it is only 16 characters long and provides almost no consumer guidance. Missing tests and changelog files in the published artifact are normal packaging practice, while the repository also reports no tests or changelog.
The repository had zero commits and zero active maintainers in the last three months, a meaningful maintenance concern even though a recent release was published.
Composer is used as a build tool, but no security-scanning tools are configured. This is a transparency and assurance gap, though it is not by itself evidence of abandonment.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.