Clear documentation, a matching MIT license, repository tests, and release notes make the package straightforward to evaluate. Organization backing and a minimal runtime dependency reduce adoption friction, while the small project footprint limits the significance of its modest popularity.
69%
Total Score
75
100
88
100
The package has four releases over about three years, with one release in the last 12 months and intervals of about four months. This is slow but plausible for a small, focused value-object library.
The repository recorded no commits and no active maintainers in the last three months. For a small library this may reflect stability, but it leaves current maintenance capacity unproven.
The project uses Composer, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap rather than a standalone adoption blocker.
The single workflow was fully analyzed with no injection, untrusted-checkout, or high-severity findings, but all six action references are unpinned. Unpinned CI dependencies weaken build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.