Usable with caveats: the package is licensed, tested, clearly documented, and its repository is active enough to support a small stable library. Its release history is sparse, no commits were recorded in the last three months, and it relies on one maintainer without a security policy.
68%
Total Score
50
100
94
80
Only one account has registry publish access. That is a thin publishing base for long-term continuity, although the linked project is owned by the same individual and is not presented as organization-backed.
The registry namespace and repository are tied to the same individual owner, which supports provenance, but there is no organization backing to broaden maintenance capacity.
The package has existed for about 7 years and 8 months but has only three releases, with a median interval of about 3 years and 6 months. One release in the last 12 months shows some continued maintenance, but the cadence is sparse.
No commits or active maintainers were recorded in the last three months. Combined with the sparse release history, this raises maintenance and abandonment concerns even though the repository was pushed recently.
The repository has no SECURITY.md or other declared security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version ^2.0 || ^3.0 | — | — |
jeroen/file-fetcher Version ~6.0|~5.0 | — | — |
jeroen/simple-cache Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.