Its Apache-2.0 licensing, clear README, minimal dependency surface, and lack of install scripts reduce adoption friction. The source is transparent but offers little evidence of ongoing review or formal security practice.
58%
Total Score
75
100
83
83
This package has only one release, published about two years ago, with no releases in the last 12 months. That may reflect a deliberately stable utility, but it provides little evidence of continued maintenance.
There were no commits and no active maintainers in the last three months. Combined with the single-release history, this leaves ongoing maintenance unproven.
The repository has no stars, forks, or watchers. Popularity is only supporting evidence, but these counts provide no external sign of adoption or community support.
The repository uses Composer, which fits the package ecosystem, but it has no detected security scanning tooling. For this small package that is a modest transparency gap rather than a severe risk.
The repository has no security policy. This does not show a vulnerability, but it provides no documented process for reporting or handling security issues.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.