The MIT license, release notes, and matching repository make the package transparent and straightforward to consume. Maintenance evidence is thin, with only two releases, no registry release in nearly three years, no recent commits, and no security policy.
60%
Total Score
67
100
83
83
Only two releases were published, both around the initial launch, and there have been no releases in nearly three years. That is a meaningful maintenance concern for a package developers may need to track over time.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the long registry release gap, this is evidence of slow maintenance.
There are no new or closed issues in the last month and two open pull requests remain unmerged. This suggests limited ongoing collaboration, though the project has no open issues.
With two stars, one fork, and one watcher, the project has little visible community adoption. Popularity is supporting evidence rather than a verdict, but this leaves limited external validation.
Composer is used for builds, but no security scanning tools are configured. The missing scanner is a hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.