The small codebase is clearly documented, tested, and licensed, with a straightforward dependency list and no install-time scripts. Its single-user ownership and lack of security tooling add little ongoing assurance.
45%
Total Score
50
75
75
Only one registry maintainer is listed, so publishing continuity depends on a single person. That is a modest concern for resilience, although the repository is also owned by that same individual and the package is small.
The package has had only three releases, all ending more than seven years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the historically regular early release interval.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no updates since 2019. The lack of recent activity materially lowers maintenance confidence.
The repository uses Composer but has no security scanning tools. This is a hygiene gap rather than evidence of unsafe code, but it provides little assurance for a package with no recent maintenance.
No security policy is present in the repository. For a small utility library this is not severe on its own, but it reduces transparency around vulnerability reporting.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.