The Apache-2.0 license, readable README, and matching source tree make it straightforward to inspect. No security policy or automated security scanning is visible, leaving limited evidence of review depth.
43%
Total Score
50
50
50
The package has only two releases, both in January 2024, and none in the following 2 years and 8 months. That long release gap is strong evidence of abandonment risk, despite the stable version designation.
The repository recorded zero commits and zero active maintainers in the last 3 months, supporting the broader evidence that maintenance has stalled.
Composer build tooling is present, but no security-scanning tools are configured. For a small four-file package this is a modest review-depth gap, not evidence of unsafe code by itself.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. This is a documentation gap rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.