The package is lightweight, clearly licensed, and documented, with a matching source repository. Its long inactivity means compatibility and bug fixes may depend on the original author.
58%
Total Score
75
100
81
75
The latest release was over six years ago, with no releases in the last 12 months. The three releases were initially close together, but the prolonged pause raises abandonment and compatibility concerns.
There are three open issues but no new or closed issues and no pull requests in the last month. This indicates little recent project activity, although the issue count alone is not severe.
Composer build tooling is present, but no security-scanning tool is reported. For a small dependency this is a modest transparency and maintenance gap, not a standalone disqualifier.
The repository is not archived, but it was last pushed over six years ago, which reinforces the maintenance concern already shown by the release history.
The repository has no security policy. That weakens vulnerability-reporting transparency, though it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.