The package has a README, tests, release notes, a matching MIT license, and a modest dependency set. Its single-maintainer project has shown no recent development or security-policy upkeep, so future compatibility fixes may be unavailable.
48%
Total Score
25
75
75
The latest release was published in July 2020, and there were no releases in the following six years. This is strong evidence that maintenance has stopped, despite the package having 15 releases overall.
The repository recorded zero commits and zero active maintainers during the latest three-month window, confirming that the long release gap reflects inactive development rather than a stable recent cadence.
Only one registry maintainer is listed. That is not inherently unsafe, but combined with the absence of recent repository activity it leaves little visible maintenance capacity or succession coverage.
The repository has no security policy, and the absence of security-scanning tools provides no documented process for handling vulnerabilities. This adds a transparency and maintenance concern, though it is less serious than the inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0 | — | — |
enesdayanc/iso4217 Version ^3.0 | — | — |
spatie/array-to-xml Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.