The package has a small, focused codebase with tests, documentation, and clear licensing. Its long inactivity and lack of security policy make future compatibility and maintenance uncertain.
43%
Total Score
100
75
75
The latest release was in September 2018, with no releases in the last 12 months. This is strong evidence of abandonment risk for a library dependency.
The repository has only 1 star and no forks or meaningful watcher base, offering little evidence of broad community validation. Popularity is supporting evidence, so this is a modest concern rather than a decisive risk.
Composer is used for the build, but no security scanning tools are configured. The missing scanning reduces supply-chain transparency, although it does not establish a defect.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.