The package is small and tested, with one runtime dependency and organization-backed ownership. Its last release and repository activity were about nine years ago, while the install script and missing security policy add maintenance and operational concerns.
42%
Total Score
50
100
75
67
The package has had no release in about nine years and none in the last 12 months, indicating severe stagnation despite 10 historical releases.
There were no commits and no active maintainers in the last three months, consistent with a repository that has been inactive for about nine years.
A post-install-cmd script runs during installation, creating additional execution and maintenance surface for consumers even though no maliciousness judgment is made here.
The artifact and repository include tests, which is a positive for this small tooling package. The missing README is a minor integration gap for developers consuming its rules.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.