The package has clear documentation, tests, an MIT license, and a simple dependency setup. Its release and commit history has been inactive for about two years and nine months, so future fixes and compatibility updates are uncertain.
56%
Total Score
75
100
83
83
Only one release exists, published about two years and nine months ago, with no releases in the last 12 months. This is strong evidence of inactivity, though the package may be intentionally stable.
There were no commits and no active maintainers in the last three months, consistent with the long release gap. This lowers confidence that defects or compatibility issues will be addressed promptly.
The repository has zero stars, one fork, and one watcher, indicating little visible adoption or external validation. Low popularity is supporting evidence only and does not outweigh the otherwise coherent package structure.
Composer build tooling is present, but no security-scanning tools were detected. For this small library, the missing scanning setup is a hygiene limitation rather than a severe dependency risk.
No repository security policy is present. This limits the transparency of vulnerability reporting, although the package's small scope and simple dependency profile partly reduce the concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
egulias/email-validator Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.