The package is clearly documented, tested, licensed, and has a focused dependency footprint. Its release history is sparse and the repository has had no commits for about three and a half months, so ongoing maintenance should be watched.
64%
Total Score
50
100
78
100
The package has only two releases across about 10 months, with a median gap of roughly seven months. This is limited evidence of sustained maintenance rather than abandonment on its own.
The repository recorded no commits and no active maintainers during the last three months. That weakens evidence of current maintenance, although the latest release was published during the assessed period.
The repository has zero stars, forks, and watchers. This provides little external validation, but popularity is supporting evidence and does not outweigh the documented, tested package structure.
Composer is used for the build, but no security scanning tools were detected. The absence of scanning is a hygiene gap rather than evidence that the release is unsafe.
Version v0.2.0 is not a stable major release, so the public API may still change. It is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.