The complete source tree, tests, MIT license, and zero runtime dependencies reduce adoption friction. Its long-standing lack of releases or commits makes future fixes and support uncertain.
58%
Total Score
50
100
83
83
The package and repository are owned by the same individual account, so there is no organizational backing shown by the collected ownership data. That leaves a relatively narrow visible support base.
The package has had only 3 releases, with the latest on November 9, 2017, and no releases in the last 12 months. This is strong evidence of a dormant release process, though the small utility's stable version may reduce the need for frequent updates.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the last push occurring in November 2017. The code may be stable, but there is no observed recent maintenance capacity.
Composer is used as the build tool, but no security scanning tools are configured. The absence of scanning is a modest hygiene gap, while the simple dependency profile limits its practical impact.
The repository has no security policy. For a small data-backed library this is not a severe risk, but it leaves vulnerability reporting and handling expectations unspecified.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.