The stable release has a usable README, release notes, an MIT declaration, and no install-time scripts. Maintenance appears dormant, with no commits in the last three months and no registry releases in nearly three years.
58%
Total Score
50
88
75
Only one registry account has publish access, leaving a thin publishing base. The linked repository is user-owned, so there is no organization backing shown to compensate for that limitation.
The package has only three releases, all concentrated over three days, and none in the last 12 months; the latest release is nearly three years old, indicating limited ongoing maintenance.
There were no commits and no active maintainers in the last three months, which reinforces the concern that maintenance has stalled.
Composer is used for the build, but no security scanning tool was detected. For this small package this is a modest transparency gap rather than a severe risk.
The repository has no security policy, reducing the clarity of vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.