The package has had no release for over 10 years and no repository commits in over 5 years. Its README, tests, MIT license, and lack of runtime dependencies make the small library straightforward to evaluate and use.
56%
Total Score
50
100
79
50
The latest release was over 10 years ago, with no releases in the last 12 months. This is a substantial maintenance concern, although the package has a five-release history rather than being an abandoned one-off.
The repository recorded no commits and no active maintainers in the last 3 months. Combined with the old release history, this indicates materially limited ongoing maintenance.
Composer is used as the build tool, but no security scanning tools are present. This is a modest transparency and hygiene gap, not evidence that the package is unsafe.
The repository has no security policy. For a small library this is a transparency gap, though the package's narrow scope and available source code reduce its practical weight.
Version 0.0.7 is not a stable-major release, so compatibility expectations are limited. It is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.