The package is licensed, has a matching source repository, includes repository tests, and uses no install-time scripts. Its small project has little evidence of ongoing support, so adopting this release carries meaningful maintenance risk.
45%
Total Score
50
100
75
75
The latest release was over two years ago, with no releases in the last 12 months. Eight releases since August 2023 show an established but now inactive release history.
The package and repository are backed by an individual account rather than an organization, so there is no visible organizational continuity to offset the inactive project history.
Composer is used for build tooling, but no security scanning tool is configured. For a small wrapper this is a hygiene gap rather than a severe adoption blocker.
The repository is not archived, but its last push was over two years ago, which is consistent with the inactive release history.
The repository has no security policy, leaving vulnerability-reporting expectations unspecified. This is a transparency gap, though the package's small scope limits its weight.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.