The repository has tests, a matching package reference, and a declared MIT license. Its single maintainer and absent security scanning leave limited oversight.
52%
Total Score
25
100
81
75
The package has only one release, published over four years ago, with no releases in the last 12 months. This is substantial evidence of stagnation, though the repository remains available and unarchived.
There were no commits or active maintainers in the last three months, consistent with a project whose last recorded push was in June 2023. This reinforces the abandonment risk from the one-release history.
Only one registry maintainer is listed, which limits publishing redundancy and increases the effect of maintainer inactivity. This is partly consistent with a small user-owned project but remains a maintenance concern.
The repository uses Composer, but no security scanning tool was detected. Build tooling is present, while security oversight appears limited.
The repository has no security policy. For a small library this is a modest transparency gap rather than a standalone reason to reject it.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.