The package is small and easy to inspect, with tests, a clear MIT license, and a release record. Its maintenance has slowed: no registry release for over two years and no commits in the last three months, while security scanning and a security policy are absent.
64%
Total Score
75
100
88
83
The package has nine releases since August 2021, but none in the last two years, indicating a meaningful maintenance slowdown for a library consumers may continue to depend on.
There were zero commits and zero active maintainers in the last three months. That is a direct maintenance concern, although it is not evidence of an archived repository.
Composer is used as the build tool, but no security scanning tool was detected. For a small library this is a moderate transparency gap rather than a severe dependency risk.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This lowers transparency but does not by itself make the release unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.53|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.