Clear documentation, repository tests, and a minimal dependency set help adoption. The MIT license and organization backing are reassuring, but the package has no recent release activity and lacks security scanning.
45%
Total Score
50
100
69
75
The signal identifies strong borrowed identity for a package resembling spatie/regex, despite zero artifact overlap and no README claim of being a fork. Consumers could select this package when they intended the much more established lookalike.
Only two releases were published, with the latest in June 2015 and none in the last eleven years. That makes ongoing compatibility and maintenance uncertain.
There were no commits or active maintainers in the last three months. Combined with the stale registry release history, this indicates limited current maintenance.
Composer is used as the build tool, but no security scanning tooling is present. This is a hygiene gap rather than proof of an unsafe release.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.