The package includes a usable README, a small dependency surface, and no install-time scripts. Its repository has no security policy or scanning, and the README does not explicitly identify the package.
40%
Total Score
0
100
71
75
There has been only one release, published in October 2023, with no releases in the following three years. That leaves little evidence of ongoing maintenance for a package intended as a dependency.
The repository recorded zero commits and zero active maintainers during the last three months, following its last push in October 2023. This is strong evidence of inactivity, with no provided maintenance signal to offset it.
The repository name matches the package, but its README does not mention the package name. That weakens package-to-repository transparency, though the matching repository name provides partial compensation.
Composer is used for the build, which is appropriate, but no security-scanning tools are configured. This is a modest repository-hygiene gap rather than a decisive risk.
The repository has no security policy. This is a transparency and incident-handling gap, although it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.