The MIT license and clear README make the package easy to evaluate. A single maintainer, no tests, and no security policy leave little evidence of ongoing support.
48%
Total Score
50
67
75
The package has only two releases, both in January 2023, with no release in about 3 years and 8 months. This is strong evidence of stalled maintenance for a dependency.
Only one registry publisher, jeybin, is listed, and the project is user-owned rather than organization-backed. A single maintainer increases continuity risk when combined with the long release gap.
A readable 826-character README documents installation and usage. The artifact has no tests or changelog, and the repository also reports no tests or changelog, leaving limited evidence of validation and project documentation.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these figures provide no community signal to compensate for the inactive release history.
Composer is used as the build tool, but no security scanning tools are reported. The missing scanning is a modest transparency gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.