The package has a clear MIT license, a small dependency surface, and no install-time scripts. Its empty README, absent tests, and lack of security policy reduce transparency, while the five-year-old single-release history leaves maintenance largely unproven.
45%
Total Score
100
64
88
There has been only one release, published in September 2021, with no releases in the last 12 months. This is strong evidence of an unmaintained package for a library dependency.
A GitHub release for this exact version includes release notes, which documents the release. The empty README and absence of tests reduce consumer guidance and maintenance evidence, although missing tests in the published artifact are normal.
Composer is used as a build tool, but no security scanning tool is configured. The missing scanner is a modest transparency gap, not a severe risk by itself.
The repository is not archived, but its last push was in September 2021, consistent with the stale release history rather than evidence of active maintenance.
The repository has no security policy. For a package handling user-facing application fields, this weakens vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.