The package is small and easy to inspect, with a README, tests, and a minimal runtime dependency. Its MIT declaration and matching repository make adoption clearer, but no security policy leaves a modest transparency gap.
65%
Total Score
50
100
83
50
Only 3 releases have appeared across 800 days, with one release in the last 12 months. The recent latest release helps, but the overall cadence is sparse.
There were no commits and no active maintainers in the last 3 months. The repository's same-day recent push and release provide some compensation, but ongoing maintenance capacity is still uncertain.
The repository has zero stars, forks, and watchers, providing no supporting evidence of community adoption or external review. Popularity is only supporting evidence, so this is a modest concern rather than a decisive risk.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tooling is present. This is a minor hygiene gap rather than evidence of unsafe code.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.