The artifact is small, clearly identified, licensed, and has only one runtime dependency. Its low activity and lack of a security policy leave maintenance and disclosure risks for adopters.
68%
Total Score
75
100
83
50
The package has existed for over 12 years with 28 releases and one release in the last 12 months, but its median release interval is about 412 days, indicating slow maintenance rather than rapid development.
There were no commits and no active maintainers in the last three months, a meaningful sign of currently dormant development. The recent repository push and long-lived release history partly offset, but do not remove, this concern.
The repository has zero stars and one fork, so there is little community visibility or external validation. Popularity is supporting evidence only, and the package's clear ownership and stable artifact compensate for some of this weakness.
Composer is used as the build tool, but no security scanning tools were detected, leaving automated security hygiene undocumented.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.