The package is small and easy to inspect, with a clear README, a minimal runtime dependency, and no install-time scripts. However, only two releases were published, both in 2018, and the repository shows no recent commits, tests, security scanning, or security policy; maintenance abandonment is a serious concern.
42%
Total Score
25
100
75
67
The package has only two releases and none in roughly eight years, which is strong evidence of abandonment for a dependency whose compatibility and API may need maintenance.
There were no commits and no active maintainers in the measured three-month period, consistent with the repository's last push being in 2018.
The four-file tree is consistent with a small wrapper library and is easy to inspect, though it provides little evidence of mature project practices.
The repository is owned by an individual account rather than an organization, so there is no provided evidence of organizational maintenance capacity.
Composer is used for the build, but no security scanning tools are configured, leaving the project without automated security hygiene evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.