Its MIT license, minimal dependency footprint, and included tests support straightforward use. However, the repository has had no commits or releases since February 2022, and it lacks a README and security policy, leaving maintenance and consumer guidance weak.
43%
Total Score
50
100
67
50
The latest release was in February 2022, with no releases in the last 12 months. This long release gap materially raises abandonment risk despite the package's earlier release history.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the extended release gap and indicating no visible ongoing maintenance.
The package includes tests, which is a small positive, but it has no README. For a library consumers must integrate, the missing usage documentation is a real transparency and ergonomics gap; the missing changelog is normal packaging practice.
Composer build tooling is present, but no security-scanning tools are configured. That weakens maintenance hygiene, especially alongside the lack of recent activity.
The linked repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a hygiene and transparency concern, though not severe on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.