The package is small and simply structured, with MIT licensing and no install-time scripts. Its maintenance record is the main concern, while the very short WIP README and absent security policy reduce confidence for production use.
42%
Total Score
50
57
50
The latest release was published in November 2022, with no releases in the last 12 months despite the package being over four years old. This is strong evidence of abandonment risk.
The repository had zero commits and zero active maintainers in the last three months, consistent with the last push in November 2022 and indicating inactive maintenance.
The artifact includes a README, but it is only 23 characters and says “WIP,” offering little guidance to consumers. Missing tests and changelog files in the published artifact are normal packaging practice and are not counted against it.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these values provide no visible community support to offset the inactivity.
Composer is used for builds, which is appropriate, but no security-scanning tools are present. This is a modest hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.