The MIT license and direct repository match make its provenance clear. Its six-file library has almost no documentation, no tests, and no security policy, leaving little evidence of maintenance quality. Pinning this version means accepting a long-unmaintained dependency.
42%
Total Score
100
67
50
This is the package's only release, published about four years ago, with no releases in the last 12 months. That long silence is strong evidence of abandonment risk.
The package includes a README, but it is only 12 characters long and provides no meaningful usage guidance. The absence of tests and a changelog is normal for published artifacts and is not counted against it.
Composer is used for the build, but no security-scanning tooling is present. This weakens supply-chain hygiene, though it is less significant than the package's prolonged inactivity.
The repository has no security policy, reducing transparency for reporting and handling issues. This is a secondary concern for a small package, but no provided signal compensates for it.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.