The package is clearly licensed, documented, and backed by an organization with a minimal runtime dependency. Its small project has no tests or security scanning, adding modest maintenance and transparency concerns alongside the aging codebase.
44%
Total Score
75
100
88
75
The package is over four years old and has had no releases in the last 12 months; all three releases were clustered on its first day, leaving no evidence of ongoing release maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and raising abandonment risk.
Composer is used for the build, which supports reproducible package handling, but the repository has no security scanning configured; this is a modest transparency and maintenance gap.
No security policy is present, limiting guidance for reporting vulnerabilities, though the package is small and has a narrowly scoped runtime dependency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.