Its MIT license, clear README, release notes, and minimal dependency surface make the package easy to inspect. The single maintainer, absent tests and security scanning, and very small user base leave limited evidence of ongoing support.
48%
Total Score
0
58
50
This is the only release, published in November 2019, with no releases in the following six years. That strongly limits evidence of maintenance and raises abandonment risk, although the repository is not archived.
There were no commits or active maintainers in the last three months, consistent with the long release gap. This leaves little evidence that defects or compatibility issues would receive attention.
The repository has zero stars and forks and only one watcher, offering no meaningful supporting evidence of a broad user or maintainer community. Popularity is only supplementary, so this reinforces rather than determines the maintenance concern.
Composer is used for the build, but no security scanning tool is configured. For a small package this is a hygiene gap rather than proof of unsafe code, but it reduces transparency.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. This is a transparency concern, though not severe on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.