Clear licensing, a useful README, and no install-time scripts improve transparency and reduce setup risk. Long-term support remains uncertain because the sole maintainer has not released or updated the project for about eight years.
34%
Total Score
25
71
75
The package has had only one release, published about 8 years and 8 months ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the stable 1.0.0 version.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the package's long release gap. This materially weakens confidence in ongoing maintenance.
Only one registry account has publish access. That is a thin publishing base and increases continuity risk, although repository activity—not access records—is the stronger maintenance evidence here.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest hygiene concern rather than evidence that the release is unsafe.
The repository is not archived, which is a positive counter-signal, although its last push was about 8 years and 10 months ago and therefore does not offset the inactivity evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.