The package includes tests, a README, and release notes for the assessed version. Its single-person project has no security policy or security scanning, leaving limited evidence of ongoing support.
48%
Total Score
25
79
83
Only two releases were published, both in April 2024, and there were no releases in the following 12 months. The long release gap is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months; its last push was in April 2024. This indicates maintenance has effectively stopped.
The package has one registry maintainer, matching the user-owned repository, so there is no organizational backing or contributor redundancy shown. This increases bus-factor risk.
Composer build tooling is present, but no security-scanning tooling was detected. That provides less evidence of ongoing maintenance hygiene.
The repository has no security policy. For a small package this is a transparency gap, though it does not by itself show that the release is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.