The four-file codebase has a clear README, MIT declaration, and release notes for this version. Composer-only runtime dependencies and no install scripts limit operational complexity, but the project offers little security-process evidence.
62%
Total Score
75
100
83
67
The package released four versions in a short burst about 15 months ago, followed by no releases in the last 12 months. That suggests maintenance may have stopped, though the project is still relatively young.
There were no commits and no active maintainers in the last three months, consistent with the long gap since the last push. This is a meaningful maintenance concern for future fixes.
The repository has zero stars, forks, and watchers. This is weak supporting evidence of adoption, but popularity alone does not establish that the package is unsafe.
Composer is used for the build, but no security scanning tools are configured. This modestly limits automated assurance for a small package.
The repository has no security policy, leaving the process for reporting and handling vulnerabilities undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.