MIT licensing, a small dependency set, and an intact source tree support straightforward integration. The organization-backed project has release notes and no install-time scripts, though its limited security process leaves less transparency.
61%
Total Score
67
100
88
75
Only one registry account has publish access, which is a limited publishing base. The organization-owned repository provides some backing, so this is a modest concern rather than a severe risk.
The package has only three releases and its latest release was about two years ago, with no releases in the last 12 months. This indicates limited ongoing maintenance despite the package's mature stable version.
The repository recorded zero commits and zero active maintainers in the last three months. Together with the old latest release, this weakens confidence that defects or compatibility issues will be addressed promptly.
Composer is used for the build, which fits the ecosystem, but no security-scanning tooling was detected. That leaves less evidence of routine vulnerability monitoring.
The repository has no documented security policy, leaving vulnerability reporting and response expectations unclear. This is a transparency gap, although it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.