The package has clear licensing, a stable release line, and a small dependency footprint. Recent project activity is thin and concentrated in one contributor, with no security policy.
65%
Total Score
50
100
88
75
The repository is owned by an individual user rather than an organization, so the concentrated contributor activity has no organizational backing shown to compensate for it.
The project has 43 releases over roughly seven years, but it has made no registry release in the last 12 months, which lowers confidence in current maintenance.
All recent commits came from one contributor, so maintenance is concentrated and vulnerable to that contributor becoming unavailable.
Only one commit was recorded in the last three months, with one active maintainer; this indicates limited recent development capacity despite the repository remaining available.
Composer is used for builds, but no security-scanning tooling was detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.