The package has clear documentation, tests, an MIT license, and no runtime dependencies, which reduce adoption friction. Its lack of a security policy and very small public footprint leave less evidence of ongoing support.
58%
Total Score
50
100
75
83
The latest release was about eight years ago, with no releases in the past 12 months. This is substantial evidence of stagnation, although the package may be stable for its narrow purpose.
There were no commits and no active maintainers in the past three months, consistent with a project that has not been actively maintained for years.
The repository has zero stars and forks and only one watcher, so there is little public evidence of adoption or community support. Popularity is supporting evidence rather than decisive on its own.
Composer build tooling is present, but no security-scanning tooling was detected. The missing scanner is a modest transparency and maintenance gap, not a severe risk by itself.
The repository is not archived, but it was last pushed about seven years ago. Its visible availability is reassuring, while the old push date still supports the maintenance concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.