The MIT license, matching repository, and minimal dependency set make the package transparent and easy to inspect. The tiny project has no install-time scripts and is not deprecated or archived, but its long-term maintenance evidence is weak.
43%
Total Score
100
63
75
The package is over seven years old, has only two releases, and has had no release in the last 12 months. This is strong evidence of abandonment risk, despite the stable 1.0.1 version.
A README is present, but the package and repository contain no tests or changelog. Missing tests reduce maintenance confidence for a library, while the absent changelog is a minor gap.
The repository has one star, no forks, and one watcher. Low adoption is supporting evidence of limited project maturity, though popularity alone does not establish that the package is unsafe to use.
Composer is used for builds, but no security scanning tooling is present. For a small package this is a modest transparency and maintenance gap rather than a severe risk.
The repository is not archived, so it remains available for maintenance. However, its last push was in December 2018, reinforcing the stale maintenance picture already shown by the release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
justinrainbow/json-schema Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.