This release appears usable and transparently packaged, with an MIT license, source repository, tests and changelog, stable versioning, no deprecation, no install-time lifecycle scripts, and frequent recent releases. However, the linked repository shows no commits or active maintainers in the last 3 months, has no security scanning or security policy, and has no observable community activity; combined with a single registry maintainer and zero stars or forks, this creates meaningful maintenance and sustainability risk. The package is not currently unfit to depend on, but its continued health should be verified before adopting it for a long-lived or security-sensitive project.
65%
Total Score
38
50
89
90
The repository records 0 commits and 0 active maintainers in the last 3 months, indicating collapsed or absent source-development activity. This materially offsets the frequent registry releases and is the strongest maintenance concern in the assessment.
The package declares 17 runtime dependencies and only 1 development dependency, creating a relatively broad transitive dependency surface that raises maintenance exposure compared with a smaller package. The signal does not show that any dependency is unsafe, so this is a moderate caution rather than a severe risk.
Only one account, Alex Schloegl, has registry publish access. This is a limited publishing redundancy signal, and the repository owner is also a user rather than an organization; actual repository activity is therefore especially important to continued support.
The repository is owned by the user account leuchtdiode rather than an organization, so there is no organizational backing signal to compensate for the single registry maintainer or absent recent commits.
There are no open issues or pull requests and no new or closed issue or pull-request activity in the last month. While a clean issue tracker can be benign, the complete absence of activity offers no evidence of an engaged support community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^3.13.0 | — | — |
symfony/cache Version ^8.1.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
laminas/laminas-i18n Version ^2.33.0 | — | — |
laminas/laminas-view Version ^2.44.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.