The package includes a clear README, a compact source tree, and no install-time scripts. Its repository is not archived and the release is stable, but the single-release history provides limited evidence of long-term support.
62%
Total Score
50
81
88
The manifest declares MIT, but the artifact license file is detected as GPL-3.0. Although a license file exists, the mismatch creates real uncertainty about which terms govern this release.
This package has only one release, published about 174 days ago, so there is little release history from which to judge sustained maintenance.
No commits and no active maintainers were recorded during the last three months. That is a meaningful maintenance concern, even though the repository is not archived.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy. For a small library this is not severe, but it reduces clarity about how vulnerabilities are reported and handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.