The package is MIT-licensed, includes a README, and has no install-time scripts. Its linked repository is not archived, but the single-maintainer project has little visible activity and limited release history.
52%
Total Score
50
81
75
Only two releases exist, with the latest about 18 months ago and none in the past 12 months. This indicates a largely inactive release process, though it does not by itself prove abandonment.
One registry maintainer is responsible for publishing the package. This is a limited publishing base, although the repository owner is also identified and the count alone does not measure actual maintenance.
The repository recorded no commits and no active maintainers during the past three months. That weakens evidence of ongoing maintenance, despite a more recent repository push being recorded.
The repository uses Composer build tooling, which supports a defined build process, but no security-scanning tools were detected. The missing scanner is a hygiene concern rather than evidence of unsafe code.
The linked repository has no security policy. This is a modest transparency gap for a dependency, but the available signals do not show a broader security-process failure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.