Usable with caveats: the package is licensed, small, dependency-light, and backed by an active-looking repository, but its maintenance record is thin. Only two releases exist across nearly three years, with no commits in the last three months and no README or tests to support consumers.
52%
Total Score
50
100
72
50
The artifact has no README, which is a meaningful documentation gap for a library consumers must integrate. The absence of tests and a changelog in the published package is normal packaging practice and is not penalized here.
Only two releases have been published since April 2023, with roughly 2 years and 9 months between releases. One release in the last 12 months provides some evidence of continued use, but the long interval limits confidence in maintenance.
There were no commits and no active maintainers in the last three months, weakening evidence of ongoing maintenance. The repository's push in December 2025 shows it was updated recently enough to avoid treating it as clearly abandoned.
The repository has zero stars and forks and only one watcher. This is weak supporting evidence, but popularity alone does not determine the health of a small package.
Composer build tooling is present, but no security scanning tools are reported. For this small package that is a transparency gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.