Healthy and suitable to use, with a small maintainer footprint. The package has clear documentation, tests, release notes, minimal dependencies, and a current unarchived repository, but recent commit activity is absent and repository security policy and workflow permissions are incomplete.
78%
Total Score
50
100
89
80
The registry namespace and repository are owned by the same individual account, so the package has direct ownership alignment. It is not organization-backed, leaving a relatively small continuity base.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, despite the latest release being in February 2026. This suggests a thin maintenance base and warrants monitoring for abandonment.
The repository has 0 stars, 1 fork, and 1 watcher, so external adoption evidence is very limited. Low popularity is supporting caution rather than a decisive health problem for a small focused library.
Composer build tooling is present, but no security scanning tools were detected. The tests and CI workflow compensate for some quality concerns, though security-process transparency is limited.
The repository has no security policy. For a small validation library this is a transparency gap rather than a severe adoption blocker, but it leaves vulnerability-reporting expectations unclear.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.