The package includes tests, release notes, a clear README, an MIT license, and no install-time scripts. Its small release history and lack of recent repository activity make long-term maintenance uncertain.
42%
Total Score
0
100
71
75
Only two releases were published, both within about one day in November 2022, and there were no releases in the last 12 months. This is strong evidence of an inactive release stream for a library dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push occurring in November 2022. No provided maintenance signal compensates for this prolonged inactivity.
The repository uses Composer build tooling, but no security-scanning tools were detected. The missing scanning is a modest transparency and maintenance gap, not a standalone adoption blocker.
No repository security policy was found. This weakens the project's documented vulnerability-reporting process, though it is secondary to the much stronger maintenance concern.
Version 0.0.2 is not a stable major release, which adds API-change risk when combined with the package's very limited release history. It is not marked as a prerelease, so this is a caution rather than a severe issue by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.