The repository is small, lightly used, and has no published security policy. The README and MIT declaration make the package easier to evaluate, but they do not offset the lack of recent project activity.
42%
Total Score
50
72
75
The package has had only two releases, both around January 2022, and none in roughly four years. That long release gap is strong evidence of abandonment risk for a dependency.
One registry maintainer is consistent with an individual-owned package, but it leaves little visible publishing capacity when combined with the long release gap.
The repository has zero stars and forks and one watcher. Popularity is not required for health, but these counters provide no supporting evidence of an active user or contributor community.
The repository uses Composer for building, providing basic ecosystem-standard project tooling. No security scanning is configured, but that is a secondary gap compared with the maintenance concerns.
The repository is not archived, which is reassuring, but its last push was in January 2022 and does not show recent maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.