The README, minimal runtime dependency set, and organization-backed repository make the package straightforward to adopt. Its small source tree and lack of security scanning leave less evidence of ongoing engineering discipline.
61%
Total Score
75
100
83
75
The package has existed for about 11 years but has only 5 releases, with no releases in the last 12 months; the latest release was about 20 months ago. Release notes for version 2.0.1 provide some transparency, but the long gaps suggest limited ongoing maintenance.
There were 0 commits and 0 active maintainers in the last 3 months. For a small stable library this may reflect infrequent changes, but together with the release history it reduces evidence of active maintenance.
The repository has 0 stars and 1 fork. This is weak supporting evidence rather than a health verdict, but it provides little external evidence of community adoption.
Composer is used for the build, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap, not evidence of unsafe behavior.
The repository has no security policy. This limits the documented process for reporting vulnerabilities, though the package's small scope reduces the significance of that gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.