The package has a clear README and a very small runtime dependency surface. Its workflow is fully analyzed and uses read-only permissions, but there is no security policy or automated security scanning.
42%
Total Score
0
50
50
This is the package's only release, published nearly four years ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance or version maturity.
The repository recorded no commits and no active maintainers in the last three months, consistent with activity having stopped over three years ago. No provided signal shows renewed maintenance.
The package has no declared license, license file, or repository license file. Developers therefore lack clear permission to use, modify, and redistribute it.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest hygiene gap that reinforces the limited transparency of the inactive project.
The repository has no security policy. For a small package this is a transparency gap rather than a severe risk, but it gives users no documented vulnerability-reporting path.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.