The package is small and lightly documented, with no tests or security policy. Its MIT declaration, README, and exact-version release notes provide basic transparency, but the project has not shown recent maintenance.
45%
Total Score
25
72
75
The package has had no release in more than three years and only three releases overall, indicating substantial abandonment risk despite its initially rapid release interval.
The repository recorded zero commits and zero active maintainers in the last three months; combined with the old latest release, this points to inactive maintenance.
One registry maintainer creates a thin ownership base and increases bus-factor risk, although the linked repository is owned by the same individual.
The repository has 16 stars, no forks, and one watcher, indicating limited external adoption and review; popularity is supporting evidence, so this is only a caution.
Composer is used as a build tool, but no security scanning tools are configured, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.