With no runtime dependencies and no install scripts, this release has limited operational complexity. The stable version and MIT declaration help, but the minimal four-file project and package-to-repository mismatch leave little evidence of ongoing support.
38%
Total Score
50
100
69
75
This is the only release, published about 3 years and 11 months ago, with no releases in the last 12 months. That is strong evidence of an unmaintained project.
Only one registry account has publish access. A single maintainer is not inherently unsafe, but combined with the one-release history it gives the project little visible maintenance capacity.
The package and repository each contain only four files, including no implementation, test, or documentation beyond a 27-character README. This provides little transparency for a dependency.
The linked repository name does not match the package name and its README does not mention the package, so the repository may not actually document or support this release.
Composer is used as the build tool, but no security scanning tooling is present. This is a hygiene gap rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.