The small codebase lacks consumer documentation and has no tests, while its lone maintainer and minimal project backing provide little evidence of support capacity. Composer packaging and a GitHub release are positives, but they do not offset the long-standing maintenance and transparency gaps.
35%
Total Score
25
50
83
The package is 1,783 days old with only three releases and no releases in the last 12 months; its latest release was in November 2021, indicating prolonged abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity since November 2021.
Neither the package metadata nor the artifact or repository contains a recognized license, leaving the legal terms for using this dependency unclear.
Only one registry maintainer is listed, which gives the package a thin publishing base; the project is user-owned rather than organization-backed, so there is no provided evidence of broader support capacity.
The published artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README is a real consumer-documentation gap; the GitHub release is a modest positive.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.