The package is small and clearly linked, with a README and no install-time scripts. One registry maintainer and no security scanning leave limited independent oversight, so long-term support depends heavily on the publisher.
55%
Total Score
50
81
100
The manifest declares MIT, while the artifact license file was detected as Unlicense. Although license files exist in both the package and repository, the mismatch creates avoidable legal uncertainty.
Only one account has registry publishing access. That is a thin publishing base for continuity, though it does not by itself show whether the source project has additional contributors.
The latest release was over a year ago, and there were no releases in the last 12 months. This indicates a slowing maintenance cadence despite seven releases overall.
The repository recorded zero commits and zero active maintainers in the last three months. The latest push coincides with the assessed release, so there is little evidence of ongoing maintenance afterward.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools are present. This is a modest transparency and maintenance gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.