The package is small and easy to inspect, with a stable version, a matching repository, and only three runtime requirements. Its documentation is minimal, and the project provides no security policy or automated security scanning.
62%
Total Score
50
100
81
50
No license is declared, no license file is present in the package, and the repository also has no license file. That leaves the legal terms for using this dependency unclear.
The package has 16 releases since November 2018, but none in the last 12 months; the latest release was about 18 months ago. This indicates a meaningful maintenance slowdown, though the historical release record is established.
The repository had no commits and no active maintainers during the last three months, consistent with about 18 months since the latest release. This weakens confidence that bugs or compatibility issues will be addressed promptly.
Composer is used for the build, but no security scanning tool is configured. For a small utility library this is a hygiene gap rather than a severe adoption risk.
The repository has no security policy. This reduces transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.