The package is small and lightly documented, with no automated security scanning; its single runtime dependency and BSD license reduce integration friction. Pin v1.2.4 only if you can accept an effectively frozen API.
42%
Total Score
0
100
71
75
The latest release was about five years ago, with no releases in the last 12 months. Only four releases overall indicate a largely inactive project.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and raising abandonment risk.
The repository has one star, zero forks, and zero watchers. This is supporting evidence of limited adoption, though popularity alone is not decisive.
Composer is used for builds, but no security-scanning tooling is configured. This is a hygiene gap rather than a severe risk by itself.
No security policy is present. For a library implementing a private API, this reduces transparency around reporting and maintenance practices.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.