The package has no README or security policy, and its repository has no automated security scanning. The MIT declaration and matching source repository provide useful transparency, but consumer guidance is thin.
38%
Total Score
0
69
75
There has been only one release, published in October 2023, with no releases in the following two years and ten months. This is strong evidence of limited ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the long-term maintenance concern rather than compensating for it.
The package has no README, leaving consumers without documented usage guidance. Missing tests and a changelog are normal for a published artifact, while the GitHub release mechanism provides some project structure.
Composer build tooling is present, but no security-scanning tools were detected. This is a hygiene gap, though it is less significant than the maintenance evidence.
The linked repository has no security policy, reducing transparency about how vulnerabilities would be reported or handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jsl/config Version ^1.0 | — | — |
jsl/ensure Version 0.3.1.1 | — | — |
jsl/router Version ^0.2.6 | — | — |
jsl/database Version ^2.6 | — | — |
cebe/markdown Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.