Usable with caveats: it is a small, clearly licensed package with regular recent releases and an active organization-backed repository. Maintenance is thin, with only one commit from one contributor in the last three months and no security policy.
72%
Total Score
67
100
81
75
All recent commits come from a single contributor, creating a narrow maintenance base. The organization-owned repository provides some handoff capacity, but no second active contributor is shown.
Only one commit was recorded in the last three months from one active maintainer. That is limited recent maintenance and lowers confidence that issues or future compatibility needs will be handled promptly.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this mainly indicates limited external validation rather than making the package unsafe by itself.
Composer is used as a build tool, but no security scanning tools are reported. The absence of scanning is a transparency and maintenance gap, though it is not severe on its own.
No repository security policy was found. This leaves vulnerability reporting and response expectations undocumented, which is a real transparency gap for a dependency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.