Usable with caveats: the package is licensed, tested, documented, non-deprecated, and backed by a matching repository. No releases in the last year and no commits in the last three months suggest maintenance may have slowed, while security-policy and scanning coverage is limited.
72%
Total Score
50
88
80
The registry namespace and repository are both owned by the same individual account, which is consistent ownership evidence but does not provide organizational backing or redundancy.
The package has six releases over roughly four years, but none in the last 12 months; this is a maintenance concern for a package that may need compatibility updates.
The repository recorded zero commits and zero active maintainers in the last three months, which materially increases the risk that maintenance has slowed or stopped.
There are only three open issues and one open pull request, but no issues or pull requests were closed or merged in the last month; this gives limited evidence of active maintenance.
Composer is used as a build tool, but no security-scanning tools were detected. The missing scanning is a transparency gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.