The MIT license, focused dependency set, README, and tests make adoption straightforward. Its small project has no security policy or scanning, so maintenance and security coverage remain limited.
65%
Total Score
75
100
86
50
The package is only 204 days old and has released twice, with the latest release about five months ago. This provides limited evidence of sustained maintenance, though the project is still relatively young.
The repository recorded 0 commits and 0 active maintainers in the past three months, indicating stalled recent development. The April release shows the project was recently active, so this is a maintenance caution rather than abandonment.
Composer build tooling is present, but no security-scanning tools were detected. This reduces automated security coverage for a package that sends data to remote API endpoints.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency and maintenance gap, not evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.