The package is small and transparent, with a matching source tree, a clear MIT declaration, and no install-time scripts. Its lack of tests, security scanning, and security policy adds little assurance, while the long maintenance gap makes future fixes uncertain.
38%
Total Score
0
100
81
88
Only two releases exist, and the latest was published in January 2018; there have been no releases in more than eight years. This is strong evidence of abandonment risk despite the stable 2.0 version.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap and leaving little evidence of ongoing maintenance.
Composer is used for the build, which is appropriate, but no security-scanning tooling is present. That weakens automated detection without proving the package is unsafe.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. The package is small, but this remains an assurance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.