The license and package-to-repository match are clear, but the tiny README and single-user ownership leave little guidance or visible support. Its Composer setup is straightforward, yet there is no security scanning or documented response process.
38%
Total Score
33
67
75
The latest release was about eight years ago, with no releases in the past 12 months. That strongly suggests the package is no longer actively maintained.
There were no commits and no active maintainers in the past three months, consistent with a project that has been inactive since 2018.
Only one registry maintainer is listed, and the project is backed by an individual account. This leaves limited visible continuity if that maintainer stops publishing.
The package includes a README, but it is only 26 characters long and provides almost no integration guidance. Missing tests and a changelog are expected packaging gaps here and are not counted negatively.
The repository is owned by an individual rather than an organization, and the registry namespace differs from the repository owner account. This indicates limited institutional backing.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.