It has a clear README, tests, MIT licensing, and a small runtime footprint. The project is backed by an organization, but its limited release history and no commits in the last three months reduce confidence in ongoing maintenance.
62%
Total Score
75
100
81
83
The package has only 2 releases over about 2 years and had 1 release in the last 12 months, with a median interval of about 573 days; this indicates a slowly maintained project.
There were 0 commits and 0 active maintainers in the last 3 months. The recent v0.2.0 release is compensating evidence that the project is not abandoned, but ongoing activity remains limited.
The repository uses Composer, and the package has only 1 runtime dependency, PHP itself, which keeps dependency and build complexity low. No security scanning tools are reported, limiting automated security coverage.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap rather than evidence of an unsafe release.
Version v0.2.0 is not a stable major release, so compatibility expectations are lower than for a 1.x package, although it is not a prerelease.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.