The package is tiny, clearly licensed, documented, and has no install-time scripts or known workflow findings. Its single-maintainer project has had no commits or releases for about two years, with no tests or security scanning.
62%
Total Score
67
100
88
67
Only one registry account can publish the package, leaving little publishing redundancy. The linked repository is user-owned rather than organization-backed, so there is no provided evidence of a broader support base.
The package has four releases since February 2023, but none in the last 12 months; the latest release was about two years ago. This indicates stalled maintenance for a dependency that may need compatibility fixes.
There were no commits and no active maintainers in the last three months. Combined with the old latest release, this is direct evidence that maintenance has stopped.
Composer is used for builds, but no security scanning tool is configured. For this small package that is a modest transparency and hygiene gap, not evidence of abandonment by itself.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a minor transparency gap for a small helper library.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.