The MIT license, clear README, and repository tests make this small utility straightforward to evaluate. Its narrow scope and stable v1.0.1 help, but ongoing maintenance evidence is limited.
58%
Total Score
50
81
50
Only two releases were published, both in March 2023, with none in the past 12 months. That is weak evidence of ongoing maintenance for a dependency last released over three years ago.
The package has one registry maintainer, creating a thin publishing base. The repository is user-owned rather than organization-backed, so there is no provided organizational context to offset that concentration.
The repository had zero commits and zero active maintainers in the past three months, indicating no recent development activity. The repository is not archived, which is a modest compensating signal but does not show active maintenance.
There are two open issues and no issues or pull requests were closed in the past month. This is limited evidence of project responsiveness and reinforces the maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. This is a minor repository hygiene gap and does not outweigh the package's otherwise inspectable structure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.