The package has a clear MIT declaration, a useful README, repository tests, and no install-time scripts. Its small runtime dependency surface and stable 1.0.0 release reduce adoption friction, but the absent security policy and scanning leave transparency gaps.
58%
Total Score
0
100
81
83
The package has had 5 releases since September 2012, but none in the last 12 months; the latest release was in May 2018. This is the main abandonment concern.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the last push in May 2018. This indicates the project is effectively inactive.
Composer is used for builds, but no security scanning tooling is present. This is a modest transparency and maintenance gap rather than evidence of unsafe behavior by itself.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. The package's long inactivity makes this gap more consequential.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.