The focused codebase has tests, a narrow dependency footprint, and no install-time scripts. Its explicit MIT license helps, but the package offers no README and lacks a security policy, leaving little guidance for users or reporters.
42%
Total Score
0
100
69
75
The last release was in September 2017, with no releases in the following 12 months and none since; this is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long period without releases.
The artifact and repository contain tests, which supports basic maintenance quality, but no README is present for consumers of this library; the missing changelog is expected for a published artifact and is not a concern by itself.
The repository has zero stars and forks and only one watcher, providing little community evidence to offset the package's long inactivity; popularity is supporting evidence rather than a verdict.
Composer build tooling is present, but no security-scanning tooling was detected. For this small, old library that is a modest transparency gap, not evidence of unsafe behavior.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.