The package is small and easy to audit, with one runtime dependency, a clear README, and an organization-backed repository. Its license metadata conflicts with the MIT license file, while no commits were recorded in the last three months. Pin this version only if the licensing ambiguity is acceptable.
62%
Total Score
75
100
78
83
The manifest declares a proprietary license while the artifact and repository contain an MIT license file. That conflict creates real licensing ambiguity despite the presence of a license file.
The package is young, with two releases over about four months and the latest published roughly four months ago. This provides limited evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers during the last three months. For a package released only about four months ago, this is a meaningful warning about ongoing maintenance.
The repository has no stars, forks, or watchers. That offers no supporting evidence of community adoption, but popularity is only secondary and does not by itself make a small package unsafe to use.
Composer is used for the build, which fits the package ecosystem, but no security-scanning tooling was detected. The missing scan is a hygiene gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.