The README remains a template, and the repository has no security policy or automated security scanning. The package is MIT-licensed and not deprecated, but those positives do not offset the maintenance gap.
43%
Total Score
100
81
50
A README is present, but its 582-character content still contains placeholders such as “DESCRIBE_THE_MODULE_HERE” and “FIRST_NAME LAST_NAME,” leaving the package poorly documented. Missing tests and a changelog in the published artifact are normal packaging practice.
The package has had no release in over two years, despite six releases concentrated within its first few weeks. That prolonged silence is a meaningful abandonment concern.
Composer is used as a build tool, but no security scanning tooling is present. This is a modest transparency and maintenance gap for a package with no recent activity.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.