The last release was over four years ago, with no commits or active maintainers in the past three months. The package is small and clearly licensed, but it has no tests, security policy, or repository reference to its published package name.
58%
Total Score
50
71
75
The artifact includes a useful README, while the absence of tests and a changelog is normal for published package contents; repository-level test and changelog evidence is also false, leaving limited project documentation beyond usage instructions.
The latest release was in April 2022, and there were no releases in the last 12 months; this indicates prolonged maintenance dormancy for a dependency.
The repository recorded zero commits and zero active maintainers during the last three months, providing no evidence of current maintenance capacity.
The repository name does not match the package name and its README does not mention the package, so the source relationship is not clearly established. This is a transparency concern, though a sub-package naming difference can be ordinary.
Composer build tooling is present, but no security scanning tooling was detected. For a small package this is a hygiene gap rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.