The MIT license and minimal dependency set make its intent clear. With one publisher and no recent repository activity, future fixes and support are uncertain.
42%
Total Score
50
100
81
75
The package has one registry maintainer, and the linked project is user-owned rather than organization-backed. The small maintainer base increases continuity risk alongside the observed inactivity.
The artifact has no README, tests, or changelog, and the repository also reports no tests or changelog. Missing tests and changelog are acceptable packaging practice, but the absent README reduces guidance for consumers of this library.
The last release was published in March 2019, and there were no releases in the past 12 months. That long period without updates is a substantial maintenance concern, though the package has a stable release history rather than erratic versions.
The repository had zero commits and zero active maintainers in the past three months, consistent with the absence of recent releases. This indicates a high abandonment risk for a library consumers may need maintained fixes for.
Composer is used as the build tool, which is appropriate for this PHP package, but no security scanning tools are present. The tooling gap is a minor additional concern rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.