The package is small and well-scaffolded, with tests, release notes, and matching MIT licensing. Repository popularity is negligible, security scanning is absent, and the repository does not identify this package.
43%
Total Score
50
71
75
Only two releases exist, and the latest was published in December 2021; there have been no releases for roughly four years and nine months. This is a substantial abandonment concern despite the repository remaining available.
Only one registry account has publish access. The linked repository is user-owned, so this is a genuine resilience concern rather than ordinary organization publishing hygiene.
The repository name does not match the package name and its README does not mention the package. That makes the package-to-source relationship less clear and warrants caution.
Composer build tooling is present, but no security scanning tools were detected. The missing security automation is a modest transparency and maintenance gap.
The repository has no security policy. This weakens vulnerability-reporting transparency, although it is less serious than the long period without releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
bdk/css-xpath Version ^1.0 | — | — |
psr/simple-cache Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.