Its MIT licensing, focused dependency set, and release notes make the small library easy to inspect. There is no repository security policy or automated security scanning, leaving transparency and oversight limited.
58%
Total Score
100
100
75
83
Only two releases were published, both in July 2019, with no releases in roughly seven years. That is substantial evidence of abandonment risk for a dependency, although the package may be intentionally stable.
Composer build tooling is present, but no security scanning tool was detected. This is a modest oversight gap rather than evidence of unsafe behavior by itself.
The repository is not archived, which preserves a path for future maintenance, but its last push was about seven years ago and does not offset the long release gap.
The linked repository has no security policy. For a package intended for application integration, that weakens the documented path for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.