Tests, release notes, a clear MIT license, and a small dependency set support basic transparency. The single-user project has little adoption and no security policy, so future maintenance remains uncertain.
58%
Total Score
25
100
75
50
The package has only two releases, both published within about two minutes on October 28, 2024, and none in the following nearly two years. This is strong evidence of stalled maintenance for a dependency.
There were zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
Only one registry account has publish access. The repository is also owned by a single user, so there is no demonstrated organizational or contributor redundancy to compensate for that narrow base.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counts provide little external evidence of maturity or community support.
Composer is used for the build, but no security scanning tools are configured. For a small package this is a hygiene gap rather than a severe defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^3.0 | — | — |
psr/simple-cache Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.