The package has a long release history and an organization-owned repository, but its small artifact has no consumer documentation or license. Recent releases are not matched by source commits, so future maintenance is uncertain.
62%
Total Score
83
75
50
No license declaration, license file, or detected license was found in the package or repository. That creates a real adoption and redistribution concern.
The published artifact has no README, tests, or changelog. Missing tests and changelog are normal for a published artifact, but the missing README weakens consumer documentation for this library.
The repository recorded zero commits and zero active maintainers over the last three months. This conflicts with the recent release history and makes ongoing source maintenance uncertain.
Composer build tooling is present, but no security-scanning tooling was detected. The missing scanner is a hygiene gap rather than evidence that the release is unsafe.
The repository has no published security policy. This modestly reduces transparency about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.