The package is a tiny, stable two-file example with MIT licensing and no install-time scripts. Its organization-backed repository is not archived, but the lack of maintenance and security documentation makes long-term reliance a liability.
47%
Total Score
50
75
83
The package has had only three releases, all clustered in October 2020, with no releases in the last 12 months and roughly 5 years 11 months since its latest release. This is a substantial abandonment concern for a dependency.
The repository recorded zero commits and zero active maintainers during the last 3 months, consistent with the package's long period without releases. No provided signal shows compensating recent maintenance.
Composer is used as the build tool, but no security scanning tool is present. The small package scope limits the impact, while the absence still weakens supply-chain hygiene.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. For a tiny educational package this is a modest concern, but it adds to the transparency gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.