The package has clear licensing, tests, and organization backing, which support routine use. Its small adoption footprint and limited security process provide less assurance than a mature alternative.
58%
Total Score
75
79
50
The package is about 2 years and 11 months old but has only 4 releases, with a median interval of about 206 days. Two releases in the last 12 months show it is not abandoned, but the cadence is sparse.
There were no commits or active maintainers in the last 3 months, indicating a current maintenance pause. The recent January release prevents this from proving abandonment, so the net impact is caution rather than danger.
The repository has only 2 stars, 1 fork, and no watchers. Popularity is not decisive by itself, but this small external footprint provides little independent evidence of maturity.
The repository has no security policy, leaving no documented channel or process for vulnerability reports. Other signals show the project is licensed and maintained at least recently, but they do not replace this process.
Version 0.2.2 is not a stable major release, so its API may still change. It is not marked as a prerelease and recent releases contain no prerelease versions, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version * | — | — |
symfony/mime Version * | — | — |
symfony/finder Version * | — | — |
league/commonmark Version * | — | — |
doctrine/inflector Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.