The package is small and well documented, with tests, a changelog, and a matching MIT license. Its lone maintainer and lack of security tooling leave little evidence of ongoing oversight.
58%
Total Score
25
100
70
50
The package has had only 4 releases since September 2013, with no releases in the last 12 months and the latest release in January 2020. This is strong evidence of dormant maintenance, although the small package scope may reduce the need for frequent changes.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history and indicating no recent maintenance capacity.
Only one registry account has publish access. That is a thin operational base for continuity, though the linked repository is owned by the same individual rather than an unrelated publisher.
Composer build tooling is present, but no security-scanning tooling was detected. The build setup supports reproducibility, while the missing scanning is a modest hygiene gap.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. This is a secondary concern compared with the long maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.