The repository includes tests, matching package names, and a clear Apache-2.0 license. Its small dependency footprint helps, but the lack of a security policy leaves limited guidance for reporting issues.
43%
Total Score
25
100
72
75
This package has only one release, published about 6 years ago, with no releases in the last 12 months. That is strong evidence of limited ongoing maintenance for a dependency.
The repository recorded zero commits and zero active maintainers over the last 3 months, consistent with a project that has been inactive for years. This materially increases abandonment risk.
The registry namespace and repository owner are the same individual account, which makes ownership clear but indicates no visible organizational backing to compensate for a thin maintenance base.
The repository has 0 stars, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these counts provide no meaningful external adoption or maintenance signal to offset the inactivity.
The repository uses Composer, which fits the package ecosystem, but it has no security scanning tools. This is a modest hygiene gap rather than a standalone reason to reject the release.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.