Its small dependency footprint and clear README make integration straightforward. The sole release was published nearly eight years ago, and the repository has had no commits in the last three months, limiting confidence in ongoing maintenance.
58%
Total Score
50
100
79
75
There has been only one release, published nearly eight years ago, with no releases in the last 12 months. This is the main maintenance concern, though the package is a small, focused utility.
There were no commits and no active maintainers in the last three months. For a package with no recent releases, this is consistent with substantially reduced ongoing maintenance.
Composer is used for the build, but no security-scanning tool was detected. The missing scanner is a minor transparency gap rather than evidence that the package is unsafe or unmaintained.
The repository is not archived, but its last push was nearly seven years ago. The unarchived state preserves the possibility of maintenance, while the old activity still supports the release-history concern.
The linked repository has no security policy. This modestly reduces disclosure transparency, but the package's focused scope and otherwise clear source structure limit its effect on the overall assessment.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.