The documented interface, MIT license, tests, and minimal runtime footprint support adoption. Long-term inactivity and the lack of a security policy make future fixes and security transparency uncertain.
58%
Total Score
75
100
79
83
The package has had no releases in roughly 9 years, with 0 releases in the last 12 months. This is a meaningful maintenance concern, though the linked repository remains available and unarchived.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with a project that has been inactive for years. This raises the risk that compatibility or security issues will not be addressed promptly.
Composer is used for the build, but no security scanning tools are present. The missing scanning is a transparency and hygiene gap rather than evidence of an unsafe release.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This matters for a filesystem interface, even though the package is small and has a limited dependency surface.
Version 0.0.4 is not marked as a prerelease, but the package remains below 1.0, so compatibility expectations are weaker. Its mature age partly offsets the lack of a stable major version.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.