The small dependency footprint and included tests and README reduce adoption friction. Its long release gap and inactive repository make future fixes and compatibility updates uncertain.
58%
Total Score
50
100
83
83
The repository is owned by an individual rather than an organization, so the project has a relatively narrow visible ownership base. This adds some continuity risk but is partly offset by the repository's package mention and included tests.
The package has had no release in about four years, with only four releases overall and none in the last 12 months. That materially raises maintenance and compatibility risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with its last push being in February 2023. This reinforces the maintenance concern from the stale release history.
The repository has four stars and no forks, indicating a small user and contributor base. Popularity is only supporting evidence, but it provides little compensating evidence for the inactivity.
Composer is used as the build tool, but no security scanning tool is reported. The missing scanner is a modest hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.