The package is tiny, documented, and has no install-time scripts. Its stable version and matching repository help, but the long lack of maintenance makes a new dependency a liability.
43%
Total Score
0
75
83
The latest release was in October 2018, with no releases in the last 12 months and only three releases overall. This is strong evidence of abandonment for a dependency that may need framework compatibility updates.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the release history and indicating no current maintenance capacity.
The repository has only 2 stars and no forks, providing little supporting evidence of broad adoption or community resilience. Popularity is supporting evidence rather than the primary concern here.
Composer is used as the build tool, but no security-scanning tooling is present. This is a modest transparency and hygiene gap, not evidence of a harmful package.
The repository has no security policy. For a small development-only utility this is a limited concern, but it leaves no documented route for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.