The repository is small, has no security policy, and still has one unresolved issue. The clear README, matching repository, MIT license, and simple dependency footprint provide useful transparency.
58%
Total Score
50
100
79
83
The repository is owned by an individual account rather than an organization, so continuity depends on a narrow owner base. The matching repository and package identity provide some compensating transparency.
This package has only one release, published 1063 days ago, with no releases in the last 12 months. That is substantial evidence of limited maintenance, although a stable data package may need fewer releases.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the single release and last push in November 2023, this raises meaningful abandonment risk.
There is one open issue and no issue or pull-request activity in the last month. On its own this is limited evidence, but it adds to the wider picture of a dormant project.
Composer build tooling is present, but no security scanning tools were detected. For a small data-focused package this is a modest transparency gap, not a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.