Usable with caveats: the package is licensed, not deprecated or archived, and its repository clearly matches the package. However, it has had no release or commit activity for about two years and ten months, with only one maintainer and limited project safeguards.
55%
Total Score
67
75
83
One registry maintainer is consistent with a small user-owned project, but it leaves little visible redundancy if that maintainer stops supporting the package.
A README is present, but its collected content appears incorrectly encoded and is difficult for consumers to read. The absence of tests and a changelog in the package is normal packaging practice, while the repository also provides no tests or changelog to compensate.
Only two releases exist, and none was published in the last 12 months; the latest release was about two years and ten months ago. This indicates a dormant project, although a small stable utility may not need frequent releases.
There were no commits and no active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
The repository uses Composer, but it has no security scanning tools. This is a modest transparency and maintenance gap rather than a severe risk for a very small package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.