The stable major release, tiny dependency footprint, tests, README, and matching source repository reduce adoption friction. No security policy or automated security scanning leaves transparency gaps; pin this version and monitor maintenance.
62%
Total Score
50
100
88
88
The package and repository are owned by the same individual account. That is consistent ownership, but it represents a single-person project rather than organizational backing.
The package has 7 releases over roughly 11.6 years, with no releases in the last 12 months and a median interval of about 15 months. This indicates slow maintenance and lowers confidence in timely fixes.
There were zero commits and zero active maintainers in the last three months. Combined with the lack of releases in the last year, this is a meaningful maintenance warning.
Composer is used for builds, but no security-scanning tools are present. For a small library this is a transparency and vulnerability-detection gap, not evidence of unsafe behavior by itself.
The repository has no security policy. This makes vulnerability reporting and response expectations less transparent.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.