The README and MIT declaration make integration and licensing clear. The repository is tiny, has no tests or security policy, and shows no recent project activity. Its single-maintainer structure also leaves limited visible continuity.
40%
Total Score
25
69
75
The package has had no releases in roughly eight years, despite four releases during its initial period; this is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long release gap and indicating no current maintenance activity.
Only one registry maintainer is listed. The matching repository is user-owned rather than organization-backed, so there is little visible redundancy if that maintainer stops publishing.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this provides no community signal to offset the maintenance concerns.
Composer build tooling is present, but no security scanning tooling was detected. For a small dependency this is a hygiene gap rather than a standalone disqualifier.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.