The MIT license, README, and direct repository match make its contents easy to inspect. It has no install-time scripts and no dependency burden, but pinning this exact version is prudent because ongoing support is unclear.
45%
Total Score
50
83
83
This is a single-release package first and last published in August 2017, with no releases in the last 12 months. That long period without a new release is a meaningful abandonment concern, despite the package remaining stable at version 1.0.0.
The package has only one registry release, so there is little release history available to demonstrate maturity or sustained compatibility.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old last push, this indicates no observable recent maintenance.
Composer is used as the build tool, but no security scanning tools are present. For a small library this is a hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap, although the package's narrow scope limits its weight.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.