Usable with caveats: it is a stable, licensed package with tests, a clear README, and matching repository ownership. However, it has had no release in over 20 months and no commits in the last three months, so maintenance appears limited.
68%
Total Score
67
88
90
Only one registry account has publish access, creating concentration risk, although the organization-backed repository provides some compensating project context.
The package has only four releases and none in the last 12 months; the latest release was over 20 months before collection, which is a meaningful maintenance concern for a dependency.
There were no commits and no active maintainers in the last three months, indicating currently limited development activity and increasing abandonment risk.
Composer is used for the build, but no security-scanning tooling is present; this is a transparency and maintenance gap, though not severe for this small library.
No security policy is provided, leaving vulnerability-reporting expectations unclear for a package that handles application sessions.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.