The package is clearly licensed, has a matching source tree, and uses no install-time scripts. Its short README and minimal project footprint provide limited transparency, while the small dependency surface reduces integration risk.
47%
Total Score
0
100
79
75
The latest release was published in June 2020, and there have been no releases in the last six years. This is strong evidence of abandonment risk for a package developers may need to rely on.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long release gap and providing no evidence of current maintenance.
Composer is used as a build tool, showing basic ecosystem-appropriate project tooling. No security scanning tools are present, which is a minor transparency gap but not decisive for this small package.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This adds a modest transparency concern alongside the stronger maintenance concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.