The small codebase is clearly licensed, documented, and free of install-time scripts. Its organization-backed repository remains available, but security coverage is thin and there is no security policy.
47%
Total Score
75
86
75
This package has only one release, published about 3 years and 9 months ago, with no releases in the last 12 months. That leaves maintenance and compatibility uncertain despite the package being mature enough to have a stable release.
There were no commits or active maintainers in the last 3 months, consistent with a repository that has seen no activity since late 2022. For a dependency, this is a meaningful abandonment concern.
Composer build tooling is present, but no security-scanning tool was detected. That is a modest transparency and maintenance gap rather than evidence of unsafe code by itself.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This adds a transparency gap for a dependency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.