Usable with caveats: the package is small, stable, licensed, correctly backed by its repository, and has repository tests, but it has had only one release and no recent development activity. The missing package README and absent security policy reduce transparency for long-term adoption.
62%
Total Score
75
100
81
50
The published artifact has no README, which makes integration less convenient for consumers, although the source repository does contain a README and tests. The source-side tests are a positive sign, so this is a transparency gap rather than a severe risk.
This is the only release, published about 1 year and 7 months ago, with no releases in the last 12 months. That may be acceptable for a small stable utility, but it provides little evidence of ongoing maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, leaving current maintenance capacity unproven. The repository is not archived and the package is backed by an organization, which partially offsets but does not remove this concern.
The repository uses Composer build tooling, which is appropriate for a PHP package. No security scanning tool is present, leaving a modest process gap, but this is not by itself evidence of abandonment.
The repository has no security policy, reducing transparency about vulnerability reporting and response. For a small utility this is a hygiene concern rather than evidence that the package is unsafe to use.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.