Healthy and suitable to depend on: it is a small, stable interface package with clear licensing, minimal runtime dependencies, and strong organizational backing. The main caveat is that no registry release has appeared in the last two years and recent repository commit activity is quiet, although the repository remains active and this release has GitHub release notes.
82%
Total Score
75
100
89
83
The package has existed for about 14 years with 12 releases, but it has had no registry release in the last two years. That is a maintenance concern, partly offset by the repository being pushed recently and this version having release notes.
The repository recorded zero commits and zero active maintainers in the last three months, which limits evidence of ongoing development. The recent push and the package's narrow, stable interface partly compensate for this gap.
Composer is used as the build tool, showing standard project tooling, but no security scanning tool was detected. The missing scanner is a modest transparency gap rather than a severe risk for this small package.
The repository has no SECURITY policy, leaving vulnerability-reporting expectations undocumented. This is a limited transparency gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.