The MIT license and single runtime dependency make the package easy to evaluate. Organization backing and a repository changelog provide useful continuity, though no security policy is published.
64%
Total Score
75
100
86
50
The package has three releases over about three years, with one release in the last 12 months and a median interval of about 13.6 months. This is a slow cadence, but the latest release is recent enough to avoid an abandonment finding.
The repository recorded zero commits and zero active maintainers in the last three months. The repository was pushed with this release, but the recent inactivity still raises maintenance risk.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no published security policy. For a small validation interface package this is a limited gap, but it leaves vulnerability-reporting expectations unspecified.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.