Usable with caveats: the package is small, licensed, documented, and backed by a matching repository, but it has had no release or commit activity for more than four years. Depend on it only if its PHP 8 support and unchanging code remain suitable for your project.
58%
Total Score
50
100
79
83
The package has only 3 releases and none in the last 12 months; its latest release was published more than four years ago. This indicates limited and possibly dormant maintenance for a library dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long gap since the latest release. That reduces confidence that compatibility or bug fixes will arrive when needed.
The repository uses Composer build tooling, but no security scanning tools were detected. For this small package the missing scanning is a hygiene gap, though not by itself a severe dependency risk.
The linked repository is not archived, which avoids the stronger abandonment signal of an explicitly retired project. Its last push was more than four years ago, so the non-archived status does not offset the stale activity.
No security policy was found in the repository, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap, but the package has no other provided signal indicating an active security issue.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.