The package is licensed, documented, and its source repository matches its name. Its tiny project has no recent maintenance activity, so future fixes and compatibility updates are uncertain.
42%
Total Score
25
100
81
88
The package has had only 4 releases, all concentrated in April 2022, with no release in more than four years. That is a substantial abandonment concern for a dependency.
There were 0 commits and 0 active maintainers in the last three months, consistent with the release history and indicating that maintenance has stopped or nearly stopped.
The registry namespace and repository owner match, but both are a user account rather than an organization. This offers little evidence of durable project backing.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and maintenance gap, not a decisive risk for this small package.
The repository has no security policy. That weakens disclosure transparency, although the package's small scope and the stronger evidence of inactivity are more important.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.