It includes tests, a clear MIT license, and a small dependency set. The repository is not archived and matches the package, but there has been no release or repository push since May 2017, leaving meaningful maintenance risk.
52%
Total Score
75
100
67
50
The package has only three releases, with the latest on May 24, 2017 and none in the last 12 months. This long release gap materially raises abandonment risk.
There are no open issues or pull requests and no recent issue or pull-request activity. While this may fit a small stable library, it provides no evidence of ongoing maintenance.
Composer build tooling is present, but no security scanning tooling was detected. For this small, old package that is a minor hygiene gap rather than a severe risk.
The repository is not archived, which is a positive compensating signal, but its last push was on May 24, 2017 and does not show current maintenance.
No repository security policy was found. This weakens transparency for reporting security issues, though the package's small scope limits the impact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
weew/contracts Version ^1.1 | — | — |
weew/helpers-string Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.