The MIT license and matching source repository make reuse and ownership clear. The repository has no security scanning or policy, and its very small scope offers limited evidence of quality.
40%
Total Score
25
72
50
The package has only one release, published about 5 years ago, with no releases in the last 12 months. This gives little evidence of ongoing maintenance.
There were no commits and no active maintainers in the last 3 months, consistent with a project that has been inactive for about 5 years.
The artifact contains only composer.json and one source file, while the linked repository matches it and adds a README. The narrow scope is not inherently unsafe but provides limited evidence of maturity.
The source repository contains a README, but there are no repository tests or changelog and the published artifact has no README. For this small library, the limited documentation and validation reduce transparency.
The repository is owned by an individual user rather than an organization, so the single registry maintainer does not benefit from visible organizational backing.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.