Documentation and tests are present, and the package has no install-time scripts or significant runtime dependencies. The license text differs from the MIT declaration, and no repository security policy or automated scanning is provided.
56%
Total Score
50
100
79
75
A license file is present, but it was detected as Apache-2.0 while the manifest declares MIT. The package is licensed, yet the mismatch warrants checking the intended terms.
Only one registry maintainer is listed, so publishing continuity depends on a single account. This is partly consistent with the matching user-owned repository but still leaves limited visible succession capacity.
The package has had no releases in the last three years, despite four releases overall; this indicates substantially slowed maintenance, though the latest release is stable rather than withdrawn.
The repository had zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating current inactivity.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance-hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.