The organization-backed repository is still active and the package includes a useful README. Its tiny footprint, missing security policy, and unclear repository association leave limited evidence for long-term support.
56%
Total Score
100
63
75
Neither a declared license nor a license file was found, leaving the legal terms for using this dependency unclear.
The latest release was about 19 months ago, with no releases in the last 12 months; the repository was pushed more recently, which partly offsets the stale registry release history.
The signal reports that the repository name does not match the package and that the package name is not mentioned in its README, creating uncertainty about the source association; the organization backing reduces but does not remove that concern.
The repository has no stars or forks and only four watchers, indicating limited external adoption; this is supporting evidence rather than a standalone maintenance verdict.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest transparency and verification gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.