Tests and a minimal dependency surface are positives. The repository does not clearly identify the package, and no security policy or scanning is provided.
32%
Total Score
0
100
50
88
The package has had no release in over 10 years; its five releases were concentrated in 2016, indicating severe abandonment risk despite an initially regular cadence.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push occurring in July 2016 and providing no evidence of current maintenance.
The published artifact includes tests and the repository also has tests, which supports basic project maturity. The missing README is a transparency and integration gap for a library.
The repository name does not match the package name, and no README package mention was available, so the linkage is less transparent even though this could reflect a sub-package naming difference.
Composer build tooling is present, but no security-scanning tooling was detected; this is a secondary hygiene gap rather than evidence of a malicious release.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.