The small dependency surface, clear README, comprehensive tests, and MIT license make the package straightforward to adopt. No security policy or automated security scanning is visible, reducing transparency around future fixes.
58%
Total Score
50
100
86
50
The package has seven releases but none in the last 12 months; its latest release was about four years ago. This is a meaningful maintenance concern, although the stable release and published release notes provide some documentation.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but current maintenance capacity is not demonstrated.
There are 63 open issues, with one new issue and no issues or pull requests closed in the last month. This suggests unresolved maintenance work, though issue volume alone is not evidence of abandonment.
Composer build tooling is present, but no security-scanning tooling was detected. That weakens automated security hygiene for a package intended as a reusable library.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap rather than a direct indication that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.