The package is a very small two-file library with no README or tests, limiting integration guidance and validation. Its MIT declaration and exact-version release notes provide basic transparency, but no security policy or scanning is present.
42%
Total Score
0
69
50
The package has had only 3 releases, with the latest in August 2018 and none in the last 12 months. This is strong evidence of abandonment for a library dependency.
There were no commits and no active maintainers in the last 3 months. Combined with the old last push, this materially increases abandonment risk.
The artifact contains only composer.json and one source file. That may suit a minimal library, but it leaves little visible evidence of validation or supporting documentation.
The package has no README, tests, or changelog, which weakens consumer guidance and validation for this library. The exact-version GitHub release notes provide a small amount of release documentation, while missing tests and changelog are not expected in the artifact itself.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no community signal to offset the lack of maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.