The package is small and straightforward to inspect, with a clear README and minimal runtime dependency set. Its maintenance evidence is too old for a new dependency, and testing and security practices are thin.
38%
Total Score
50
100
72
83
The package has had only two releases, both in April 2017, and none in roughly nine years. That is strong evidence of abandonment risk despite the stable v1.0.1 release.
One registry maintainer is consistent with a small package but leaves little visible publishing redundancy or maintainer capacity to reduce abandonment risk.
There are no open issues or pull requests and no activity in the past month. While a small stable package may have little issue traffic, this provides no evidence of ongoing maintenance alongside the old repository state.
The repository has one star, one fork, and one watcher, providing very limited community evidence or support capacity. Popularity is only supporting evidence, but it reinforces the maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. That leaves a small supply-chain hygiene gap without proving the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^3.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.