The package has a clear README, tests, matching source repository, and an MIT license. Its missing security policy and single-user maintenance base leave less assurance for long-term support.
67%
Total Score
50
100
88
83
The package and repository are owned by the same individual account, providing direct ownership but no organizational backing to offset the thin maintainer base.
Only two releases have appeared, with none in the last 12 months and roughly 17 months since version 1.1.0. This is a meaningful maintenance concern, though the package is still relatively small and has not been deprecated.
There were no commits and no active maintainers in the last three months. Combined with the long release gap, this lowers confidence in ongoing maintenance.
Composer is used for build or package management, but no security scanning tools are present. The missing scanner is a hygiene limitation rather than evidence of abandonment by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations unspecified.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.