The package is licensed, documented, and has no install-time scripts, making adoption straightforward. Its small repository has limited validation and security transparency.
58%
Total Score
25
81
75
The package has only one release, published about 2 years and 11 months ago, with no releases in the last 12 months. This is strong evidence of stalled maintenance, although the package may be intentionally complete.
The repository had zero commits and zero active maintainers in the last 3 months, consistent with the package's single-release history. This materially increases abandonment risk.
The package and repository are backed by the same individual user account rather than an organization, so there is no visible organizational maintenance capacity to compensate for the single-maintainer profile.
Composer is used as the build tool, but no security scanning tools are configured. For a small package this is a transparency and validation gap, though it is not evidence of malicious behavior.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. The small project scope limits the severity but does not remove the transparency gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.