Its MIT license, matching repository, and lack of install scripts make the small artifact straightforward to inspect. The one-person project has little supporting activity or security process.
48%
Total Score
50
75
83
The package has only one release, published about eight years ago, with no releases in the last 12 months. This strongly raises abandonment risk, although a deliberately small package may not need frequent feature releases.
The repository has had no commits and no active maintainers in the last three months, consistent with the long release gap. There is no provided evidence of current maintenance capacity.
The repository has 1 star, 0 forks, and 1 watcher, so there is little community evidence to compensate for the lack of recent activity. Low popularity alone is not disqualifying for a small package.
The repository uses Composer, which fits the package ecosystem, but it has no security scanning tools. The missing scanning is a modest process gap rather than evidence of an unsafe release.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a meaningful transparency gap for a dependency, though it does not by itself show a security defect.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.