The repository has no tests, security scanning, or recent issue activity, and its documentation is only 11 characters long. The MIT declaration and matching repository provide basic transparency, but do not offset the lack of maintenance evidence.
38%
Total Score
25
71
75
The package has had only 3 releases, all concentrated in April 2015, with no release in the last 11 years. This is strong evidence of abandonment for a library dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history showing no activity since 2015.
Only one account has registry publish access. Because the repository is user-owned rather than organization-backed, this indicates a thin publishing base and limited continuity if the maintainer stops working on it.
The package includes a README, but it is only 11 characters long and the repository has no tests or changelog. Missing tests and changelogs are normal in published artifacts, while the extremely limited consumer documentation is a real transparency gap.
Composer is used as a build tool, which is appropriate for this package, but no security scanning tool is configured. The missing scanning is a hygiene gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.