The package is small and understandable, with a clear README, tests, an MIT declaration, and a minimal runtime dependency. Its lack of a security policy adds a modest transparency concern alongside the inactive project.
56%
Total Score
50
100
86
83
The repository is owned by an individual account rather than an organization, so there is no provided organizational backing to offset the thin maintenance evidence.
The package shipped 16 releases in a brief burst, then had no releases in the following 19 months. That long silence is a meaningful maintenance concern despite the initially active cadence.
The repository recorded zero commits and zero active maintainers in the last three months, following a last push about 19 months ago. This indicates sustained inactivity and raises abandonment risk.
Composer build tooling is present, but no security-scanning tooling was detected. The missing scanning is a modest process gap rather than evidence of unsafe code.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This reduces transparency for a package intended to run inside applications.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.