The package has a clear MIT license and no install-time scripts, but its artifact lacks a README for consumers. The single-release history, minimal repository activity, and repository/package name mismatch provide too little evidence of durable maintenance.
38%
Total Score
56
75
Only one release exists, published about 20 months ago, with no releases in the last 12 months. That leaves substantial uncertainty about ongoing maintenance.
The package has no README, which weakens consumer transparency for a small library. Missing tests and a changelog are normal in published artifacts and are not concerns by themselves.
The repository name does not match the package name, and no README mention was available. The source may therefore not clearly belong to this package, which weakens provenance confidence.
The repository has zero stars and forks and one watcher, offering no supporting evidence of community use or review. Popularity is only supporting evidence, so this is a minor concern.
Composer is used for builds, but no security scanning tools are present. This is a hygiene gap rather than evidence that the release is unsafe to depend on.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.