The clear README, MIT license, and small dependency surface make the package straightforward to inspect and integrate. Its release and repository activity stopped about two years ago, with no tests or security policy to support ongoing maintenance.
42%
Total Score
25
100
72
75
The package has made three releases, all clustered within about one day, and has had no release in roughly two years. That provides strong evidence of stalled maintenance for a package users may need to depend on.
There were no commits and no active maintainers in the last three months. Combined with the repository's last push being about two years ago, this indicates a stalled project rather than merely a quiet short period.
The repository is owned by an individual account rather than an organization. That is not inherently unhealthy, but it means there is no observed organizational backing to compensate for the thin maintenance evidence.
The repository has zero stars and zero forks, with one watcher. Popularity is only supporting evidence, but these values provide little external evidence of adoption or community support.
Composer is used as a build tool, which fits the package ecosystem, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.