The package is clearly licensed and easy to inspect, with a tiny dependency surface. Its source has not changed since 2022, and the linked repository does not identify the package, so pinning it is a liability.
38%
Total Score
0
100
50
83
This is the only release, published about four years ago, with no releases in the last 12 months. That is strong evidence the package is inactive.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its last push being about four years ago. This materially increases abandonment risk.
The repository name does not match the package name and its README does not mention the package. That makes package ownership and source provenance unclear, beyond an ordinary monorepo naming difference.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but it provides no supporting evidence of active community use.
The repository uses Make and Composer, which supports reproducible local work, but has no security-scanning tooling. This is a minor transparency gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.