The MIT license, direct repository match, and small runtime dependency footprint make the code straightforward to inspect. The repository has no tests or security policy, adding maintenance and transparency concerns. Use only if this unmaintained module fits your needs and you can support it yourself.
43%
Total Score
75
100
81
75
The artifact includes a README and release notes for this version, while the absence of packaged tests and a changelog is normal packaging practice. The repository itself also reports no tests or changelog, limiting transparency somewhat.
The package has only one release, published about six years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a dependency receiving ongoing use.
The repository recorded no commits and no active maintainers in the last three months, consistent with its last push being about six years ago. Organization backing does not compensate for absent recent maintenance.
Composer build tooling is present, but no security-scanning tooling was detected. That weakens automated assurance, although it is a secondary concern compared with the long maintenance gap.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap for a package intended to be integrated into an application.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.