The package has only five releases over three years and no documented security policy. Its small dependency surface, tests, MIT declaration, and recent push reduce—but do not remove—the maintenance concern.
62%
Total Score
50
100
81
75
Five releases across roughly three years, with three in the last year, shows ongoing but relatively infrequent maintenance.
All three recent commits came from one contributor, leaving maintenance dependent on a single active contributor; the repository owner is an individual rather than an organization.
Three commits in the last three months show recent activity, but the volume is modest for a maintained package.
The repository name does not match the package name, and the collected README-mention value is null, so package-to-repository identity is less transparent than usual.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.