The tiny repository offers little evidence of consumer readiness, with no README, tests, changelog, or security scanning. It is not archived and has no install scripts, but one maintainer and no release activity since 2023 weaken long-term support.
40%
Total Score
50
57
75
The latest release was published in April 2023, with no releases in the last 12 months and only four releases overall. This is substantial evidence of stalled maintenance for a package still at version 0.0.4.
No declared license or license file was detected in the package or repository. This creates a real legal and transparency gap for dependents.
Only one registry maintainer is listed. The linked repository is user-owned rather than organization-backed, so there is little visible redundancy if that maintainer stops supporting the package.
The package has no README, tests, or changelog, while the exact version does have a GitHub release. Missing tests and changelog are normal packaging gaps, but the absent README matters for a small library consumers must integrate.
Composer is used for builds, but no security scanning tools are present. This is a modest transparency and maintenance gap, not evidence that the release is unsafe by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.