The package is small and clearly documented, with a matching license and a simple dependency set. Those strengths are offset by limited security process and no recent development activity.
66%
Total Score
50
100
88
83
The repository is owned by an individual account rather than an organization. This is not inherently unhealthy, but it provides less visible institutional backing for a package with only one registry maintainer.
The package has existed since January 2017 but has only 5 releases, with no releases in the last 12 months and a median interval of about 554 days. This indicates a slow maintenance cadence, though the latest release was published in December 2024.
There were no commits and no active maintainers in the last 3 months. Combined with the slow release history, this is evidence of currently inactive development and raises maintenance risk.
Composer is used for builds, but no security scanning tooling is configured. For a small library this is a process weakness rather than a standalone severe risk.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This lowers transparency, although it does not by itself make the package unfit.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.