The package is small and focused, with a clear README, a matching source repository, and few runtime dependencies. Its long release gap and inactive recent commit record increase maintenance risk, while one registry maintainer and no security policy limit transparency.
62%
Total Score
50
100
88
75
Only one account has registry publish access. That is a limited publishing base and increases continuity risk if the maintainer becomes unavailable.
The registry namespace and repository are owned by the same individual account, so ownership is coherent. It does not provide organizational redundancy or broader backing.
The package has had 3 releases, all clustered in November 2022, with 0 releases in the last 12 months. This long release gap is a meaningful maintenance concern, though the stable v1.0.2 version reduces release-churn risk.
The repository records 0 commits and 0 active maintainers in the last 3 months. Combined with no registry releases in the last 12 months, this points to slowing maintenance.
The repository uses Composer, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.