Its MIT license and single runtime dependency keep adoption straightforward. The small, package-matched repository is easy to inspect, but it lacks tests, security scanning, and a security policy, leaving limited evidence of ongoing care.
42%
Total Score
0
100
67
75
The package has only two releases, with the latest published in January 2018 and none in the last 12 months. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and providing no evidence of current maintenance.
The artifact includes a README, while missing tests and a changelog is normal packaging practice and is not a health gap under the package-scaffolding rules. The repository also has no tests or changelog, limiting project transparency somewhat.
Composer is used as a build tool, but the repository has no security-scanning tools. The build setup is present, though security-maintenance evidence is limited.
The linked repository has no security policy, reducing transparency about vulnerability reporting and maintenance expectations. This is a secondary concern beside the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.