The focused package has a clear README, a license, and only one runtime dependency. Ongoing support is difficult to verify, with no recent repository activity and unresolved project work.
40%
Total Score
50
100
79
83
The package has only two releases, with the latest published about 7 years ago and none in the last 12 months. This strongly limits evidence that current framework or platform changes are being handled.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, while its last push was about 6 years ago. That is strong evidence of inactive maintenance.
There were no new or closed issues or pull requests in the last month, and 3 issues plus 1 pull request remain open. This suggests unresolved maintenance needs, though the project is small.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest verification gap that adds to the limited maintenance evidence.
The repository has no security policy. For a small package this is a transparency gap rather than a severe dependency risk, but it leaves vulnerability-reporting expectations unclear.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.