The package has a valid MIT license and a directly matching README, while its small artifact is easy to inspect. Its lack of a security policy adds a minor transparency concern; pinning this release is prudent only for low-risk use.
42%
Total Score
25
72
83
The package has had no releases in the last 12 months, and its latest release was over three years ago. This is strong evidence of abandonment risk despite seven total releases.
There were zero commits and zero active maintainers in the last three months, consistent with the repository's last push being over three years ago. This materially increases abandonment risk.
The repository is owned by an individual user rather than an organization, so the small registry maintainer base is not offset by visible organizational backing.
The repository has only 2 stars and 1 fork, providing little independent evidence of maturity or ongoing community support. Popularity is supporting evidence, so this is a secondary concern.
Composer build tooling is present, but no security scanning tooling was detected. That is a modest maintenance and transparency gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.