It includes a clear MIT license, README, changelog, and matching repository, which make integration transparent. The repository has no security policy, no security scanning, and very little community activity, so ongoing support would be limited.
38%
Total Score
0
71
75
The package has had no releases in roughly 7 years; all 12 releases arrived in a brief burst around July and August 2019. This is strong evidence of abandonment risk for a dependency.
There were zero commits and zero active maintainers in the last 3 months, consistent with the roughly 7-year release gap. This materially increases the risk that compatibility or maintenance issues will go unanswered.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these very low counts provide little evidence of broad review or community support.
Composer build tooling is present, but no security scanning tools were detected. That weakens ongoing supply-chain hygiene, especially for a package containing many bundled frontend assets.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency and maintenance gap, though it is not severe by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.