The package is clearly licensed, stable, and tied to an organization-owned repository with a readable package guide. Its small footprint and lack of security policy provide less assurance than a mature library, despite frequent releases.
72%
Total Score
83
100
90
88
There were zero commits and zero active maintainers in the last three months, a meaningful maintenance concern that conflicts with the package's otherwise frequent release history.
The repository has 1 star and no forks or watchers, indicating limited external adoption and review. Popularity is supporting evidence only, so this lowers assurance modestly rather than determining the verdict.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so consumers have no documented reporting or response process for vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version 3.19.0 | — | — |
arikaim/http Version ^1.0.0 | — | — |
arikaim/utils Version ^1.0.0 | — | — |
erusev/parsedown Version ^1.7 | — | — |
arikaim/collection Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.