It has an MIT license, tests, a README, and backing from a Tencent organization. Its single runtime dependency and clean repository setup reduce adoption friction, but the project provides limited recent maintenance evidence.
64%
Total Score
83
100
83
83
The package has only two releases, with the latest published in December 2020 and none in the last 12 months. This is a meaningful maintenance concern for a dependency, though the stable version and narrow scope reduce the risk somewhat.
The repository recorded zero commits and zero active maintainers in the last three months. Its last push was in March 2022, so current maintenance capacity is weak despite the repository remaining available.
Composer is used for the build, but no security-scanning tooling was detected. The build setup is present, while the missing scanning provides less assurance for ongoing maintenance.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. This is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.