The project has one registry maintainer, no security policy, and no security scanning, leaving limited maintenance and disclosure capacity. Its MIT license, focused dependency set, matching repository, and usable README provide some transparency, but the long inactivity remains the main concern.
42%
Total Score
25
100
75
50
The package has only two releases, with no releases in more than five years; the latest release was in November 2020. This strongly raises abandonment risk despite the reasonable 91-day median interval between its first releases.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release inactivity. The repository is not archived, but that does not offset the lack of recent work.
Only one registry account has publish access, and project backing identifies a personal rather than organizational owner. This leaves little visible publishing redundancy, although the registry count alone does not prove inactive development.
The repository has zero stars, one fork, and one watcher, providing little evidence of community review or shared maintenance. Popularity is supporting evidence rather than a verdict, so this reinforces rather than determines the score.
The project uses Composer but has no detected security scanning tools. That reduces automated oversight for dependency and source risks, with no other provided security process compensating for it.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.