It has a clear README, tests, MIT licensing, and minimal dependencies. Its sparse release history, no commits in the last three months, and absent security policy or scanning reduce confidence in ongoing maintenance.
62%
Total Score
50
100
79
50
The package has only 3 releases over about 4 years, with a median interval of roughly 749 days, although one release appeared in the last 12 months. This indicates a mature but very slow maintenance cadence.
There were 0 commits and 0 active maintainers in the last three months. Together with the sparse release history, this suggests limited current maintenance capacity.
Composer is used as the build tool, providing standard project tooling, but no security scanning tool is configured. The missing scanning is a modest transparency and hygiene concern.
The repository has no security policy. For a small library this is not severe, but it leaves vulnerability reporting and response expectations undocumented.
Version 0.3 is not a prerelease, but the package has not reached a stable major version. That increases compatibility uncertainty for consumers.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.