Clear documentation, repository tests, licensing, and a small dependency surface support adoption. However, the package has had no commits or releases for about 18 months, and its single-maintainer project has no security policy or automated security scanning.
58%
Total Score
50
100
81
50
This release is the package's only recorded release, published about 18 months ago, with no releases in the last 12 months. That limits evidence of ongoing maintenance.
There were zero commits and zero active maintainers in the last three months. This is the strongest evidence that current maintenance capacity is weak.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap, not evidence that the package is unsafe.
The linked repository is not archived, but its last push was about 18 months ago, consistent with the lack of recent releases and suggesting stalled maintenance rather than archival.
The repository has no security policy. That leaves vulnerability reporting and response expectations unclear for a library consumers may integrate directly.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.