The MIT license, clear README, matching repository, and non-deprecated status support adoption. The small codebase lacks tests and security scanning, while its workflow uses two unpinned actions.
43%
Total Score
0
75
75
The package has had only two releases, with the latest on September 12, 2020, and none in the last 12 months. This long period without releases is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package's prolonged release inactivity. This materially lowers confidence in ongoing maintenance.
The artifact includes a README and the repository is documented as using GitHub Releases, which helps consumers understand the package and its release process. The absence of tests is a modest maintenance concern for a library.
Composer build tooling is present, but no security scanning tools were detected. That leaves a meaningful transparency and maintenance gap, although it is not severe on its own.
The repository has no security policy, reducing transparency about vulnerability reporting and maintenance response. This is a secondary concern compared with the lack of recent development.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.