The small dependency footprint, clear README, tests, and matching MIT license make the package easy to evaluate and integrate. However, its release and commit activity is largely inactive, and the repository has no security scanning or policy.
58%
Total Score
0
100
75
75
The package has had only 3 releases, all clustered in July 2020, with no releases in the last 12 months. This is strong evidence of inactivity for a package whose latest release is now about six years old.
There were 0 commits and 0 active maintainers in the last 3 months. Combined with the old release history, this indicates a project with limited current maintenance capacity.
The repository has 1 star, 0 forks, and 2 watchers. Low adoption is supporting caution about community review and continuity, though popularity alone does not make a small stable library unhealthy.
Composer is used for the build, but no security-scanning tool was detected. This is a hygiene gap that matters more when maintenance activity is already sparse.
The repository has no security policy. This modestly reduces transparency around vulnerability reporting, but it is not severe enough to outweigh the available source, tests, and license.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.