This is a small, clearly licensed Composer package with a matching organization-owned repository, minimal runtime dependencies, no install-time scripts, stable v1.0.2 releases, and no registry deprecation or dangerous workflow findings. However, the repository shows no commits or active maintainers in the last 3 months, the package and repository contain no tests or changelog, the README is only 12 characters long, and no security policy or security scanning is present. The latest release and repository push are recent, which partly offsets the lack of recent commit activity, but the limited transparency and uncertain ongoing maintenance make this usable with caution rather than a strong default dependency.
62%
Total Score
67
100
83
90
A README is present and GitHub Releases are used, but the README is only 12 characters long and neither the artifact nor repository contains tests or a changelog. For a small two-source-file library, the absence of tests and documentation is a genuine maintenance and transparency gap.
The repository has zero commits and zero active maintainers in the last 3 months, which is a meaningful maintenance concern. The recent release and push provide some compensating evidence, so this indicates caution rather than severe abandonment.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is neutral for a tiny package with no reported problems, but it also offers little evidence of an active user or maintainer community.
The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but these counters provide no external adoption or resilience signal for this dependency.
Composer is used as the build tool, fitting the package ecosystem, but no security scanning tools are configured. The missing scanning lowers supply-chain transparency somewhat without making the package unfit on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.