The package has tests, a declared MIT license, and only two runtime dependencies. Its repository does not clearly identify the package, and the project lacks a security policy, reducing transparency for a library dependency.
43%
Total Score
0
100
63
83
The six releases were concentrated in September 2024, with no release in roughly two years and none in the last 12 months. This indicates a release history that has stopped rather than an actively maintained package.
There were no commits and no active maintainers in the last three months, consistent with the repository having received no updates since September 2024. This materially raises abandonment risk.
The repository name does not match lucite/utils, and no README package mention was available. The repository may not clearly belong to this package, which weakens provenance transparency.
The repository has zero stars and forks and only one watcher. This is supporting evidence of limited adoption and project visibility, though popularity alone does not determine health.
Composer is used for the build, but no security scanning tool is configured. The missing scanning is a modest transparency and maintenance gap, not evidence of a defect by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/http-message Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.