The MIT declaration, release notes, and organization ownership provide limited transparency. No security tooling or policy is visible, and the repository shows no broader project activity.
42%
Total Score
100
100
57
67
This is the only release, published about eight years ago, with no releases in the last 12 months. That is strong evidence of stagnation for a library dependency.
The artifact and repository each contain only four files, including two source files and no documentation or test structure. A small library can be compact, but this leaves little visible project evidence.
The exact version has GitHub release notes, which documents its initial release. However, the package has no README, tests, or changelog, leaving limited evidence for consumer guidance or verification.
The repository has zero stars, forks, and watchers. Popularity is not required for a healthy package, but combined with the single old release it provides no supporting adoption signal.
Composer is used for the build, but no security scanning tools are reported. That weakens supply-chain hygiene evidence without proving the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.