A README, tests, MIT licensing, and a small dependency set make the release easy to evaluate. The repository has no recent recorded commits or security scanning, so future fixes and oversight are uncertain.
60%
Total Score
50
100
81
88
The package has only 2 releases since September 2019, with no release in the last 12 months and a median interval of about 3 years 9 months. This is a meaningful maintenance concern for future fixes.
The repository shows 0 commits and 0 active maintainers in the last 3 months. This weakens evidence of active maintenance, although the repository is not archived.
The repository name does not match the package name and its README does not mention the package. Although this can occur with subpackages, here it reduces confidence that the linked repository clearly belongs to this release.
Composer build tooling is present, but no security scanning tools were detected. For a small library this is a modest oversight risk rather than a severe defect.
No security policy was found, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.