The package is small and easy to audit, with a clear README, MIT licensing, and no install-time scripts. Its single-maintainer project has had no commits or releases for about two years, and it has no security scanning or policy, so future fixes may be slow.
58%
Total Score
67
100
88
75
One registry maintainer is consistent with the repository being owned by the same individual, but it leaves limited visible publishing capacity if that maintainer becomes unavailable.
The package has had no releases in the last 12 months, and its latest release was about two years ago. This is a meaningful maintenance concern, though the small, stable package may require fewer updates.
There were no commits and no active maintainers in the last three months, consistent with the roughly two-year release gap and indicating limited ongoing maintenance.
The repository uses Composer, which fits the package, but no security scanning tools were detected. The absence is a modest transparency and maintenance gap for a dependency.
The repository has no security policy. For a small package this is not severe by itself, but it provides no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.