Its MIT license, test coverage, and dependency-free design make the small codebase easy to inspect. The missing security policy and minimal project activity leave little evidence of ongoing support.
45%
Total Score
50
100
63
75
The package has only one release, published about eight years ago, with none in the last 12 months. This is strong evidence of abandonment risk, although the package is small and narrowly scoped.
The repository is owned by an individual account rather than an organization, so the single maintainer provides limited visible project backing. This aligns with the package's otherwise small maintenance footprint.
There are no new issues or merged pull requests in the last month, and one pull request remains open. This provides no evidence of current maintenance activity.
The repository has only 2 stars, 1 fork, and 1 watcher. Low popularity is supporting evidence of limited adoption, but it is not decisive for a small utility.
Composer is used for builds, but no security scanning tools are configured. The lack of scanning is a hygiene gap rather than a standalone reason to reject the package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.