The source includes tests, a changelog, and a matching MIT license, but it has no security policy. Its minimal dependency set helps, while the fork’s lack of activity leaves future fixes and compatibility uncertain.
40%
Total Score
25
100
69
75
The package is about 9 years old with 72 releases, but it has had no releases in the last 12 months and its latest release was in December 2016. This strongly increases abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with no development since December 2016. That leaves little evidence of capacity to fix compatibility or maintenance issues.
The registry namespace and repository owner are the same individual account, with no organization backing shown. This does not prove a problem, but it provides limited evidence of institutional maintenance capacity.
The linked repository name does not match the package name and its README does not mention the package. This is a transparency concern, although the package description identifies it as a fork.
The repository uses Composer for builds, but no security-scanning tools were detected. The build tooling is appropriate, while the missing scanning is a minor hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.