The small library has a clear MIT license, a usable README, and repository tests. Its slow release pace, no recent commits, and minimal repository adoption make long-term maintenance uncertain.
60%
Total Score
50
100
83
50
The package has only three releases over about 2 years and 4 months, with one release in the last 12 months and a median interval of about 10 months. That is a slow maintenance cadence for a dependency.
The repository recorded zero commits and zero active maintainers during the last three months, which is a concrete maintenance concern despite the recent release timestamp.
The repository has zero stars and forks and only one watcher. Popularity is not required for a small stable library, but this provides little supporting evidence of maturity or community visibility.
The repository uses Composer build tooling, but no security-scanning tools were detected. For a small package this is a hygiene gap rather than a severe dependency risk.
No repository security policy was found, reducing transparency for vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.0|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.