The source is small and offers little documentation or security-process evidence. Organization ownership and a clear MIT declaration provide some reassurance, but this release is not a current stable dependency.
43%
Total Score
75
58
75
Only two releases exist, both effectively dating from September 2021, with no releases in the last 12 months. That makes this specific release substantially stale despite the linked repository being active more recently.
There were no commits and no active maintainers in the measured three-month period. This weakens evidence of ongoing maintenance, although the recent repository push prevents treating the project as clearly abandoned.
The repository name does not match the package name, and no README package mention was found. That raises uncertainty about whether the linked repository is the intended source for this package.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest assurance gap rather than a standalone adoption blocker.
No security policy was found in the linked repository. For a small package this is a process gap rather than proof of unsafe code, but it reduces transparency for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.