The codebase is tiny but has a README, tests, and an MIT license. Registry and repository activity stop at the first 2018 release, leaving no evidence of ongoing maintenance or security review.
38%
Total Score
75
75
50
This is the package's only release, published about 8 years ago, with no releases in the past 12 months. That strongly raises abandonment risk despite the package not being deprecated.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release history and indicating no current maintenance capacity.
Composer is used for builds, but no security-scanning tools are present. That is a modest hygiene gap and does not by itself establish a security problem.
The repository has no security policy, so consumers have no stated process for reporting or handling vulnerabilities. This is an additional transparency gap for an otherwise inactive project.
The latest version remains v0.0.1 and is not a stable major release, providing little evidence that the API or implementation matured beyond its initial publication.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.