The package is small and straightforward, with a README, minimal runtime dependencies, and no install-time scripts. Its only two releases and no commits since February 2023, plus no license or security policy, make long-term adoption a concern.
52%
Total Score
0
100
79
75
There were no commits and no active maintainers in the last three months. Combined with the last push in February 2023, this indicates prolonged inactivity and raises abandonment risk.
No declared license, license file, or repository license file was detected. This creates a real adoption and redistribution concern because the usage terms are unclear.
Only two releases were published, both in February 2023, with no releases in the last 12 months. This provides limited evidence of ongoing maintenance for a package now more than three years old.
Composer is used for project tooling, but no security scanning tool is present. That is a modest transparency and maintenance gap rather than a standalone reason to reject this small package.
The repository has no security policy. For a small utility this is not severe by itself, but it leaves vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.