The package has clear documentation, a matching source repository, and only one runtime dependency. Its last release and repository update were nearly five years ago, with no tests or security scanning, so future maintenance is uncertain.
42%
Total Score
50
100
69
75
The package has had no releases in the last 12 months, and its latest release was nearly five years ago; four total releases show a small, inactive project history.
The source repository is owned by an individual account rather than an organization, so the inactive history has no demonstrated organizational backing to offset it.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no visible community signal to offset the stale release history.
Composer is used for the build, but no security scanning tools are configured. This is a hygiene gap, though it does not outweigh the stronger maintenance evidence by itself.
The repository is not archived, which preserves a path for maintenance, but it was last pushed nearly five years ago and provides no evidence of recent activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.