Usable with caveats: it has clear licensing, documentation, tests, and a linked repository, but only one release exists and the repository has had no commits or active maintainers in over a year. Its very small user base and lack of a security policy add maintenance risk.
58%
Total Score
25
69
83
There were no commits and no active maintainers in the last three months, consistent with the long gap since the initial release and raising abandonment risk.
The registry namespace and repository owner are the same individual account, providing direct ownership continuity, but there is no organization backing to compensate for the single-person maintenance risk.
The package has only one release, published over a year ago, with no releases in the last 12 months. That leaves limited evidence of sustained maintenance.
The repository has zero stars and forks and only one watcher. Popularity is not decisive by itself, but this provides no supporting evidence of broad adoption or review.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a transparency gap, though it is not by itself evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spiral/stempler Version ^3.15 | — | — |
topthink/think-view Version ^2.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.