The MIT license and lack of install-time scripts reduce adoption friction. However, this is a very small, single-maintainer project with no security policy or scanning, so there is limited evidence of ongoing care.
42%
Total Score
50
71
75
The package has had no release in more than five years: all 13 releases arrived around its March 2021 launch, with none in the last 12 months. That is strong evidence of stagnation for a dependency.
Only one registry maintainer is listed, and the project is backed by an individual account rather than an organization. This leaves limited visible maintenance capacity if that maintainer stops work.
The repository has 0 stars and 0 forks, with only 1 watcher. Popularity is not decisive, but these counters provide little supporting evidence of active community use or oversight.
Composer is used for builds, but no security scanning tooling is present. For a small library this is a meaningful transparency and maintenance gap, though not a severe risk by itself.
The repository has no security policy. That weakens vulnerability-reporting transparency, although the package's clear MIT licensing and small scope partly reduce the concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.