The package is small and clearly tied to its source tree, with a readable README and minimal runtime dependencies. Tests and automated security scanning are absent, so ongoing maintenance would be hard to verify.
52%
Total Score
50
75
100
The package declares a proprietary license and has no license file, creating a significant legal and redistribution concern for an open-source dependency.
Only one registry maintainer is listed. This is a thin publishing base for a user-owned project and increases continuity risk if that maintainer becomes unavailable.
The package has six releases but none in the past three years; the last release was on August 29, 2023. That long publishing gap raises abandonment concerns despite the earlier rapid release cadence.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the extended release gap and indicating no current maintenance activity.
Composer is used for builds, but no security scanning tools are present. The missing scanning is a transparency and hygiene gap, though it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.