The package has a tiny runtime dependency surface and includes tests, a README, and organization-backed ownership. However, it has had no release in over three years and no recent commits; the linked repository also does not identify this package, so maintenance and provenance deserve caution.
58%
Total Score
75
100
81
75
The package has made no release in more than three years, with zero releases in the last 12 months. That is a meaningful sign of slowing maintenance, although the package has an established release history.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of current maintenance capacity. The repository is not archived, which is only a limited compensating signal.
The repository name does not match the package and its README does not mention the package, so the source relationship is not clearly established. Organization ownership and the matching package file tree reduce, but do not remove, this provenance concern.
The repository uses Composer but reports no security-scanning tools. Build tooling supports reproducibility, while the absence of scanning modestly reduces maintenance transparency.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.