A clear README, matching repository, and MIT license make the package easy to understand and adopt. Its lack of tests and security tooling is a modest concern, while the long period without maintenance limits confidence in future fixes.
58%
Total Score
50
86
50
The package has only three releases and none in roughly four years and ten months, indicating that maintenance has stopped or become very infrequent. The stable 1.0.2 version partly offsets this for a small utility, but not the lack of recent updates.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push in November 2021. This is the strongest evidence of limited capacity for future fixes.
Composer is used for builds, which supports reproducible package management, but no security-scanning tools are present. The missing scanning is a modest hygiene concern rather than evidence of an unsafe release.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. This is a transparency gap, though the package’s small scope limits its weight.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.