The package is MIT-licensed, lightweight, actively released, and has no install-time scripts. Recent repository work is sparse and entirely dependent on one contributor, with no security policy or automated security scanning.
70%
Total Score
50
100
94
75
The registry and repository are both owned by the same individual account, so there is no visible organization backing to offset the concentrated contributor base.
One contributor made 100% of the single recent commit, leaving maintenance dependent on one active person.
Only one commit was recorded in the last 3 months, indicating limited recent development activity despite the frequent registry releases.
Composer is used for builds, but no security scanning tools were detected, reducing automated checks for dependency or repository issues.
The repository has no security policy, which leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.