The MIT license, matching repository, and minimal dependency profile are reassuring. There is no security policy or automated security scanning, leaving limited maintenance transparency.
40%
Total Score
0
100
75
50
Only two releases exist, with the latest published in March 2021 and none in the following five years and six months. This strongly raises abandonment risk for a framework integration.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but that does not offset the absent recent work.
The repository has zero stars, forks, and watchers, providing no evidence of a broader user or maintainer community. Popularity is supporting evidence rather than a verdict, so this reinforces but does not create the main concern.
Composer is used for the build, showing basic ecosystem tooling, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance gap.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. This matters more because the project also shows no recent maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.