The MIT license and focused six-file tree make the package easy to inspect. Organization backing is present, but security documentation is absent; pinning this release would be prudent.
38%
Total Score
72
50
This package has only one release, published in October 2018, and none in the last 12 months. That leaves substantial abandonment risk for a dependency.
The repository has zero stars, one fork, and one watcher. Popularity is only supporting evidence, but these very low figures provide little evidence of broad review or community support.
Composer is used as the build tool, but no security scanning tool is configured. This is a hygiene gap rather than a standalone reason to reject the package.
The repository is not archived, but it was last pushed in October 2018. The unarchived status is positive, while the long-standing lack of repository activity remains a maintenance concern.
The repository has no security policy. For a small package this is a transparency and response-process gap, though it is less serious than the lack of maintenance activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.