The source is tiny and easy to inspect, with release notes for this version and no install scripts. Its lack of licensing and security policy leaves important adoption and maintenance questions unresolved.
40%
Total Score
75
88
The package has had only two releases, both on December 4, 2022, and none in the last 12 months. That is strong evidence of abandonment risk for a dependency.
Neither the package nor the linked repository declares or includes a recognized license. This creates a concrete transparency and adoption risk.
The repository uses Composer build tooling, which fits the package ecosystem. No security scanning tools are present, leaving a modest maintenance-hygiene gap.
The repository has no security policy. For a small package this is a hygiene gap rather than a standalone severe risk, but it reduces transparency for reporting and handling issues.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.