It has a clear MIT license, a focused seven-file implementation, and an organization-backed repository. Its tiny audience and lack of security tooling add little reassurance for future maintenance.
32%
Total Score
50
64
The package has had no release in about ten years, with zero releases in the last 12 months. Its nine releases were concentrated at the beginning of the project, providing little evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance activity.
The repository has only 2 stars, 1 fork, and 4 watchers. Low popularity is supporting evidence rather than a verdict, but it provides little external maintenance or review signal here.
Composer is used as a build tool, but no security scanning tools were detected. This is a hygiene gap rather than proof of unsafe code, and it matters more given the lack of recent maintenance.
The repository is not marked archived, which avoids an explicit abandonment signal, but it was last pushed about ten years ago and therefore does not compensate for the inactive commit history.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.