The MIT license, matching repository, and focused dependency set make the package easy to inspect and integrate. Missing tests, security scanning, and security guidance leave little evidence that changes or vulnerabilities are actively managed.
42%
Total Score
75
100
63
83
This is the package's only release, published in September 2020, with no releases in roughly six years. That long period without updates is strong evidence of abandonment risk.
The package includes a readable README and has a GitHub release, but it has no tests or changelog. Missing tests and a changelog reduce maintenance transparency for a library consumers integrate directly.
There are no open issues or pull requests and no activity in the last month. While a quiet issue tracker is not inherently unhealthy, here it provides no evidence of ongoing maintenance.
The repository has zero stars and forks, with five watchers. Popularity is only supporting evidence, but these counts provide little external evidence of maturity or community support.
Composer is used for the build, but no security scanning tools are present. This is a modest hygiene gap rather than a standalone reason to reject the package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.