The package is small, documented, and has a clear MIT license with no install-time scripts. Its lone maintainer, absent tests and security scanning, and no commits for over two years make future fixes uncertain.
55%
Total Score
50
100
79
75
Only one account has registry publishing access. That is workable for a small package, but it leaves little visible redundancy if the maintainer becomes unavailable.
The latest release was over two years ago, and there were no releases in the last 12 months. This indicates substantially reduced maintenance activity despite the package having eight releases overall.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long gap since the latest release and raising abandonment concerns.
The repository has zero stars and forks and only one watcher. Popularity is not required for a healthy small package, but these figures provide no supporting evidence of broad community adoption.
Composer is used as the build tool, but no security-scanning tool was detected. This is a modest hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.