The documented, tested artifact, MIT license, and clean install setup are reassuring. The immature version and missing security policy add uncertainty for long-term adoption.
45%
Total Score
0
100
79
75
There were no commits and no active maintainers in the last three months, despite the repository being available. This is the strongest evidence of current abandonment risk.
The package has made three releases, all clustered in July 2024, with no releases in the last 12 months. This strongly indicates an inactive release line.
Composer build tooling is present, but no security scanning tools were detected. That is a meaningful hygiene gap, though it is not evidence of malicious behavior by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear. This matters more for a library intended for direct application use.
Version 0.0.3 is not a stable major release, so its API and maintenance expectations remain less mature than those of a 1.0-or-later package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.