The package has a clear MIT license, a focused four-file artifact, and no install-time scripts. Its small scope keeps the maintenance burden modest, but ongoing support is not yet demonstrated.
64%
Total Score
50
100
88
83
The repository is owned by a user account rather than an organization, so the project does not show organization-level backing to compensate for its narrow maintainer footprint.
This is a young package, about 7 months old, but it has only one release and no subsequent version to show sustained maintenance.
The repository recorded zero commits and zero active maintainers over the past three months. For a package with only one release, that leaves ongoing maintenance unproven.
Composer is used for the build, but no security scanning tool is configured. The missing scanning is a modest transparency gap rather than evidence of abandonment.
The repository has no security policy, which weakens its vulnerability-reporting transparency, though this is a hygiene concern rather than a standalone dependency blocker.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version ^2.0|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.