Clear documentation and tests make the small library easier to adopt. MIT licensing, low runtime dependencies, and no install-time scripts reduce friction, but the single-maintainer project has had no recorded activity since January 2023.
55%
Total Score
50
100
79
75
Only one registry maintainer is listed, leaving limited apparent publishing redundancy for a user-owned project. This is a modest resilience concern rather than evidence of abandonment by itself.
The package has had no release in about 3 years and 8 months, despite six releases concentrated in January 2023. This is a substantial maintenance concern for a dependency.
There were zero commits and zero active maintainers in the last three months, consistent with the repository having stopped receiving changes after January 2023.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a hygiene gap, not a severe dependency risk on its own.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This lowers transparency but does not by itself make the release unfit.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.