The README explains installation and usage, and the package has a small, inspectable codebase with a clear MIT license. Its only release and repository activity are from April 2023, with no recent commits or security policy, so maintenance risk is significant.
43%
Total Score
25
79
75
This is the package's only release, published about 3 years and 6 months ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package having been inactive since April 2023.
Registry publishing is controlled by one maintainer account, which creates a thin ownership base for a package with no recent activity. The linked repository is also user-owned rather than organization-backed.
Composer is used for the build, but no security-scanning tool is configured. The package remains straightforward to inspect, so this is a modest hygiene concern.
The repository has no security policy, leaving no documented channel or process for reporting security issues. This is a maintenance and transparency gap, though not as severe as the inactivity evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.