It has a stable 1.0.1 version, no install-time scripts, and a declared LGPL-3.0-or-later license. The single-maintainer project has no README or security policy, reducing transparency and making long-term support less clear.
56%
Total Score
50
79
83
Only one registry maintainer is listed, leaving a thin publishing base. The linked repository is user-owned rather than organization-backed, so there is no provided evidence that a broader team compensates for this.
The package contains no README, tests, or changelog, and the repository also reports none. Missing tests and changelog are acceptable for a published artifact, but the missing README reduces consumer transparency for this library-style extension.
The package has had only two releases, both published in January 2025, with no releases in the following 20 months. That weakens evidence of ongoing maintenance, although a small stable extension may not need frequent releases.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with roughly 20 months without a release. This is a meaningful abandonment risk for future compatibility fixes.
Composer is used as the build tool, which fits the package ecosystem, but no security-scanning tooling is reported. This is a modest transparency gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.