The MIT license, readable README, and matching repository make the package easy to inspect. Its small dependency set and lack of install scripts reduce exposure, but project safeguards remain limited.
42%
Total Score
0
100
78
83
The last release was about eight years ago, with no releases in the past 12 months. This is strong evidence that the package is abandoned despite its four-release history.
The repository has recorded zero commits and zero active maintainers in the past three months, consistent with the long release gap and indicating no current maintenance.
The repository has zero stars, forks, and watchers, providing no community evidence to offset the inactive maintainer profile. Popularity is supporting evidence only.
Composer is used for builds, but no security-scanning tooling is present. That is a maintenance and assurance gap, though it is secondary to the lack of recent activity.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This lowers transparency but is not severe enough to determine the verdict alone.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^3.7 | — | — |
symfony/yaml Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.