The five-file package is easy to inspect, with clear usage instructions and an MIT license. Its tiny scope limits exposure, but there is no evidence of ongoing maintenance or a documented security process.
46%
Total Score
0
69
50
The package has made no releases in nearly five years; its three releases were concentrated within about a day in November 2021. That strongly suggests abandonment, despite the stable 1.0.2 version.
There were no commits and no active maintainers in the last three months, consistent with the nearly five-year release gap and increasing abandonment risk.
The repository has zero stars and forks and only one watcher. Popularity is not required for a small helper, but this provides no supporting evidence of community use or oversight.
Composer is used for the build, but no security-scanning tooling is present. This is a minor supply-chain hygiene gap rather than evidence of unsafe behavior.
The linked repository is not archived, but its last push was nearly five years ago, so the non-archived status provides little evidence of active maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.