The small package has a clear source match, a usable README, stable versioning, and no install-time scripts. Its single registry maintainer, absent license, and lack of security scanning reduce transparency and resilience despite organization backing.
56%
Total Score
67
75
75
No declared license, license file, or repository license file was detected. This creates a material legal and transparency gap for dependency use.
Only one registry account has publish access, which creates a limited publishing safety net. The organization-backed repository provides some compensation, so this is a moderate concern rather than a severe one.
The package has 32 releases since November 2015, but its latest release was in September 2021 and there have been no releases in roughly five years. This is a meaningful maintenance concern, though the stable release history shows it was previously established.
The repository recorded no commits and no active maintainers in the last three months. Combined with the old last push, this indicates prolonged inactivity and raises abandonment risk.
Composer is used as a build tool, showing basic ecosystem integration, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.