The package includes tests, a clear MIT declaration, and a matching repository, but it has no security policy or automated security scanning. Its organization backing and non-archived status do not offset the long-standing lack of release and commit activity.
43%
Total Score
50
71
83
Only one release was published, on May 20, 2021, with no releases in the last 12 months. This is strong evidence of stagnation for a package intended as a maintained dependency.
There were no commits and no active maintainers in the measured three-month period. Combined with the single historical release, this materially raises abandonment risk.
Composer is used for builds, but no security scanning tooling is configured. The missing scanning is a hygiene gap, though it is less significant than the maintenance evidence.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This lowers transparency for a package with no recent maintenance activity.
The latest version remains v0.0.1 and is not a stable major release, indicating limited maturity. It is not marked as a prerelease, which provides only a small compensating signal.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.