The MIT license, four modest runtime requirements, and a matching README make integration clear. A small repository with one registry publisher and no security scanning leaves less evidence of long-term support.
70%
Total Score
50
100
83
88
The package has seven releases over 709 days, but only one release in the last 12 months. That suggests a modest and possibly slowing maintenance cadence rather than abandonment by itself.
The repository recorded zero commits and zero active maintainers during the last three months. With no other recent activity signal to compensate, this weakens confidence in ongoing maintenance.
The repository has three stars, no forks, and one watcher, indicating a very small user base. Popularity is only supporting evidence, so this modestly lowers maturity confidence rather than determining the verdict.
Composer build tooling is present, but no security-scanning tool was detected. For a small PHP library this is a transparency and hygiene gap, though not evidence of immediate unfitness.
The repository has no SECURITY policy. This reduces clarity about vulnerability reporting and response, but does not by itself indicate that the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.