Tests, documentation, licensing, and a small dependency surface make the package straightforward to adopt. The registry has seen no release since 2016, and the reported 1.0.0 differs from the latest listed 0.1.3. The repository is not archived and was pushed in 2024.
61%
Total Score
50
100
79
50
The package has four releases, but none in the last 12 months and its latest release was in 2016. This long registry gap is a meaningful maintenance concern despite the repository having a later push.
There were no commits or active maintainers in the preceding three months, indicating currently limited development activity. The 2024 push provides some compensating evidence but does not remove the caution.
Composer build tooling is present, but no security scanning tools were detected. This is a modest repository hygiene gap rather than a severe dependency risk.
The repository has no security policy, reducing transparency about vulnerability reporting and response. This is a minor concern for a small library, not evidence of unsafe code.
The assessed version is 1.0.0 while the registry reports 0.1.3 as the latest version, creating release metadata inconsistency that warrants checking before adoption.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.