Usable with caveats: this is a small, clearly backed package with a stable release, recent publication, minimal runtime dependencies, and no install-time scripts. Repository activity has stopped for three months, with no tests, security scanning, or security policy, so ongoing maintenance and review capacity are limited.
68%
Total Score
75
100
89
83
The repository recorded no commits and no active maintainers in the last three months. The recent release partly offsets this, but the lack of current development activity is a real maintenance concern.
The repository has no stars or forks and only two watchers. This is weak supporting evidence, though the package’s narrow institutional purpose means low popularity alone does not make it unsafe to use.
Composer build tooling is present, but no security scanning tools are configured. For a small package this is a hygiene gap rather than a severe risk, yet it limits automated oversight.
The repository has no security policy. That reduces transparency about vulnerability reporting and response, although the package appears small and has a limited dependency surface.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.