The package is small and clearly identified, with a readable guide and a matching source repository. Its MIT licensing and stable version help, but the project has little operational visibility for future fixes.
60%
Total Score
67
83
75
Registry publishing is controlled by one person, and the repository is user-owned rather than organization-backed. That creates a thin apparent maintainer base and increases continuity risk.
Only two releases have been published, and none appeared in the last 12 months; the latest release was about 15 months ago. This is a meaningful maintenance concern for a package intended to integrate with an evolving platform.
There were no commits from any active maintainer in the last three months, consistent with the long release gap. This lowers confidence that fixes will arrive promptly.
The repository has one star and no forks, providing little external evidence of review, adoption, or community support. Popularity is only supporting evidence, but this does not offset the maintenance concerns.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.