Documentation, tests, and an MIT license make adoption straightforward. The small dependency set and organization-owned repository add useful context, but expect limited ongoing support.
60%
Total Score
75
100
79
50
This package has only one release, published about 2 years and 9 months ago, with no releases in the last 12 months. That is meaningful evidence of limited maintenance activity.
There were no commits and no active maintainers in the last 3 months. For a package with only one old release, this is a clear sign of weak recent maintenance.
The repository has no stars or forks and only one watcher. This is weak supporting evidence, but it is not decisive for a small, focused library backed by an organization.
The repository has no security policy. This is a transparency and reporting gap, though it is less serious because the package has clear source, tests, and licensing.
Version 0.1.0 is not a stable major release, which suggests a less mature API. The absence of prerelease labeling partly reduces that concern but does not offset the limited release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^2.0 | — | — |
psr/event-dispatcher Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.