The package has clear documentation, tests, and an MIT license, but its only release was in 2017 and repository activity has stopped. The lack of a security policy adds a smaller transparency concern.
46%
Total Score
50
100
81
75
This package has only one release, published about 9 years ago, with no releases in the last 12 months. That is strong evidence of limited ongoing maintenance for a dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with the last push being in 2021, this indicates stopped maintenance.
There is one open issue and no issues or pull requests were opened or closed in the last month, consistent with a quiet project.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
No security policy was found in the linked repository, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.