The repository has no recent commits and no security policy, while the package remains small, tested, documented, and free of runtime dependencies. Its MIT declaration and lack of deprecation or install scripts reduce adoption friction, but maintenance appears largely dormant.
58%
Total Score
50
100
81
88
The package has made 3 releases, with none in the last 12 months; its latest registry release was nearly 9 years ago. This is a substantial maintenance concern, although the repository was pushed more recently.
There were no commits and no active maintainers in the last 3 months, reinforcing that current maintenance is inactive. The older repository push provides only limited compensation.
Composer build tooling is present, but no security-scanning tool was detected. For a small library this is a hygiene gap rather than evidence that the release is unsafe.
The linked repository is not archived and was last pushed in October 2022. That is better than an archived project, but the push is still several years old relative to this release assessment.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.