The package has a clear MIT license, useful README, release notes, and no install-time scripts. Its small maintainer base, absent security policy, unpinned workflow actions, and long maintenance gap make future support uncertain.
57%
Total Score
50
81
67
One registry publisher account indicates a thin publishing base. The repository is user-owned rather than organization-backed, so there is no provided organizational backing to compensate for that limitation.
Only two releases exist, with none in the last 12 months; the latest release was about 2 years and 7 months ago. This is strong evidence of limited ongoing maintenance.
There were no commits and no active maintainers in the last three months, supporting the conclusion that maintenance has stalled.
Composer is used for builds, but no security-scanning tools are configured. For a PHP library, this is a meaningful hygiene gap, though it is not evidence of unsafe code by itself.
The linked repository is not archived, and it was last pushed about 2 years ago. The unarchived status is positive, but the old push date aligns with the maintenance concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.