This is a licensed, stable, non-deprecated package with a directly matching repository, a substantial README, repository tests, a small dependency surface, and recent release activity including two releases in the last 12 months. The main concerns are that repository commit activity shows no commits or active maintainers in the last three months, the project appears to rely on a single individual maintainer, repository popularity is very low, and no security policy or security-scanning tooling is present. Overall it appears usable, but its limited maintenance capacity and modest security transparency warrant monitoring before making it a critical dependency.
68%
Total Score
63
100
89
90
Only one registry maintainer is listed. This is a genuine continuity and bus-factor concern for a user-backed project without organizational ownership evidence.
The repository is owned by an individual user rather than an organization, providing limited visible project backing and reinforcing the single-maintainer continuity concern.
There were 0 commits and 0 active maintainers in the last 3 months, indicating currently stalled development and increasing abandonment risk despite recent releases.
The repository has only 3 stars, 2 forks, and 1 watcher. Low popularity is supporting caution about external validation, but it is not by itself evidence that a small package is unsafe to depend on.
Composer build tooling is present, but no security-scanning tools are configured, leaving security-process transparency limited.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.