The package includes tests, a stable release, a clear source tree, and organization backing. Its license files conflict, and the repository has no security policy or scanning, which leaves useful transparency gaps.
65%
Total Score
75
100
79
75
The artifact and repository contain license files, but the manifest declares GPL-2.0 while the detected license is MIT. The mismatch creates uncertainty about the terms governing this release.
The package has five releases over about four years, but none in the last 12 months; the latest release was about 13 months ago. This indicates slowed maintenance for a library that may need ongoing compatibility updates.
The repository had no commits and no active maintainers in the last three months, consistent with the broader release slowdown and raising abandonment risk.
Composer is used for builds, but no security scanning tool is configured. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.