Usable with caveats: the package is small, licensed, tested, and its repository is active enough to support the latest release. However, it has only two releases across about seven years and no commits in the last three months, with minimal adoption and limited security practices.
68%
Total Score
50
100
83
88
The repository is owned by an individual rather than an organization, so the single registry maintainer represents a genuinely narrow maintenance base rather than normal organization publishing hygiene.
The package has only two releases since September 2019, with roughly six years between releases; although one release arrived in the last 12 months, the overall history shows limited maintenance cadence.
There were no commits and no active maintainers in the last three months, which is a meaningful maintenance concern for a library with only one apparent maintainer.
The repository has one star, zero forks, and one watcher, indicating very limited external adoption and review; this is supporting caution rather than a standalone health verdict.
Composer build tooling is present, but no security scanning tooling was detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.