The package includes a usable README, clear MIT licensing, and a small dependency surface. Its single maintainer and minimal repository leave little evidence of ongoing support, so future fixes may be difficult.
58%
Total Score
25
100
81
50
The package has had no releases in roughly 27 months and has only three releases, all clustered on its first day. That is the strongest evidence of limited ongoing maintenance.
There were zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving little evidence of current maintenance capacity.
Only one registry account has publish access. This is not inherently unsafe, but it leaves the release process dependent on a narrow maintainer base with no compensating organization backing shown.
Composer build tooling is present, but no security-scanning tool is reported. The missing scanning is a modest transparency gap in an otherwise small package.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This is a hygiene concern rather than evidence of an immediate defect.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.