Usable with caveats: it has a clear MIT license, documentation, and a non-archived repository, but this is a one-release package with no commits or releases for about 19 months. Its small project footprint and absent security policy add maintenance uncertainty.
52%
Total Score
50
100
78
90
There were zero commits and zero active maintainers in the last three months. Combined with the single-release history, this is a meaningful abandonment risk.
Only one release exists, and there have been no releases in the last 12 months. That limited history provides little evidence of ongoing maintenance.
The repository has zero stars and forks and only one watcher. Low popularity is supporting evidence rather than a verdict, but it offers little external validation or community resilience.
Composer is used as the build tool, which is appropriate for PHP packaging, but no security scanning tooling is present. The missing scanner is a modest transparency gap rather than proof of unsafe code.
The linked repository is not archived, but its last push was about 19 months ago, so the non-archived status does not demonstrate active maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.