The package is small and easy to audit, with no runtime dependencies, a clear MIT declaration, and tests. Its long period without updates makes future compatibility and maintenance uncertain; pinning this version is prudent for legacy use.
42%
Total Score
0
100
67
75
There has been only one release, published in September 2017, with no releases in the last 12 months. That long publication gap is strong evidence of abandonment risk for a dependency.
The repository has had zero commits and zero active maintainers in the last three months, consistent with the package having been inactive since 2017. This substantially lowers confidence in ongoing maintenance.
The repository has zero stars and forks and one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little evidence of an active user or contributor community.
Composer is used for the build, but no security scanning tool is configured. For a small legacy helper package this is a hygiene gap, not evidence of an unsafe release by itself.
The repository has no security policy. That weakens vulnerability-reporting transparency, though it is less significant for this small, inactive package than the maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.