The package is small and easy to inspect, with MIT licensing, a clear README, one runtime dependency, and no install scripts. Its source matches the package and uses Composer, but there is little evidence of ongoing review or security oversight.
43%
Total Score
25
100
75
88
The package has only two releases, with none in the last 12 months; its latest release was published in June 2017, leaving a long maintenance gap.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history's long-term inactivity.
Only one registry account has publish access, and the project is user-owned rather than organization-backed; this leaves limited visible maintenance capacity.
Composer is used for project tooling, but no security scanning tools are present, reducing evidence of ongoing dependency or source review.
The repository has no security policy, which is a transparency gap, though the package is small and has a limited dependency profile.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.