Its MIT license, focused dependency set, tests, changelog, and release notes make the small package easy to inspect. The limited repository activity and lack of security policy leave support and oversight uncertain.
52%
Total Score
50
100
83
75
The package and repository are both owned by the same individual account, which is consistent with a small personal project but does not provide organizational backing.
The package has had three releases, with the latest in May 2018 and none in the last 12 months. This long period without releases is meaningful evidence of limited ongoing maintenance.
There were zero commits and zero active maintainers in the last three months. Combined with the old last push, this indicates little evidence of active support.
The repository has zero stars and forks and only one watcher. Popularity is not decisive for a small package, but this provides no additional evidence of community support.
Composer is used for builds, but no security-scanning tools are present. This is a modest transparency and oversight gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.