The package is small and clearly documented, with a minimal runtime dependency and no install-time scripts. Its repository remains unarchived and was pushed in April 2024, but the registry release is old and recent commit activity is absent.
61%
Total Score
100
86
75
The package has only three releases, with none in the last 12 months, and version 1.3.1 was published in September 2018. This indicates a mature but potentially stale dependency, though the linked repository was updated more recently.
Composer is used for build and dependency management, but no security scanning tooling is present. For this small package that is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy. This weakens the documented process for reporting and handling vulnerabilities, although it does not by itself show abandonment.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.