Usable with caveats: the package is licensed, stable, documented, tested in its repository, and has no install scripts or deprecation notice. However, it has had no release or commit activity for about two years, so future maintenance and compatibility should be verified before adopting it.
68%
Total Score
50
100
88
75
The repository is owned by an individual rather than an organization, so the project has a relatively narrow apparent backing structure. That is partly offset by the package's long release history and repository test coverage.
The package has 16 releases since 2017, but none in the last 12 months and the latest release was about two years ago. This is a meaningful maintenance concern for a dependency, despite its established history.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release. The repository is not archived, but current maintenance capacity is not evident.
The repository uses Composer build tooling, but no security-scanning tool was detected. For this small library the missing scanner is a transparency gap, though it is less significant than the maintenance signals.
No security policy was detected, leaving vulnerability-reporting guidance unclear. This is a modest transparency gap for a dependency, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.