The package includes a clear MIT license, a useful README, tests, and no install-time scripts. Its small dependency surface and active, non-archived source repository provide some support despite limited project maturity.
62%
Total Score
50
100
75
67
Only two releases arrived within minutes of each other, and there have been no releases in the last 12 months despite the package being about 17 months old. This weakens confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers over the last three months. Combined with the lack of recent registry releases, this is meaningful evidence of slow or paused maintenance.
The project uses Composer build tooling, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap for a dependency project.
No repository security policy was found. This does not show a vulnerability, but it leaves the process for reporting and handling dependency issues unclear.
Version 0.0.2 is not a stable major release, so the public API may still change substantially. It is not marked as a prerelease, which provides limited compensation.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.