Its scope is narrow, with a clear README, MIT declaration, and only one runtime dependency. The nearly five-year gap since the last release and commit activity lowers confidence in ongoing maintenance, while the repository remains active rather than archived.
60%
Total Score
50
100
83
50
The latest release was in December 2021, with no releases in the last 12 months and a median interval of about 596 days. This is a substantial maintenance concern for a dependency, though the package has a long release history and is not deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the nearly five-year release gap. The repository is not archived, which provides some reassurance but does not show current maintenance.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are present. For a small data-message package this is a modest transparency gap, not a severe risk.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. This is a hygiene concern rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.