It has a clear MIT license, matching repository, usable README, and minimal dependency footprint. The project lacks security scanning and has no tests, limiting confidence in future changes.
40%
Total Score
0
100
75
83
The package has only one release, published about 8 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk for a dependency.
The repository has had zero commits and zero active maintainers in the last 3 months, with its last push about 8 years ago. The stable code may still work, but there is no evidence of ongoing maintenance.
The repository has 1 star, 0 forks, and 0 watchers. Popularity is only supporting evidence, but these figures provide little external evidence of adoption or review.
Composer is used for the build, which fits the package, but no security scanning tools are configured. This is a modest transparency and maintenance gap.
The repository has no security policy. For this small middleware package it is a limited transparency gap rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.