The package is tiny and easy to inspect, with an MIT declaration and no install-time scripts. Its only release was over 11 years ago, with no subsequent release activity, tests, or security policy, so maintenance risk is substantial.
38%
Total Score
100
56
67
There has been only one release, published over 11 years ago, with no releases in the last 12 months. That long period without updates is strong evidence of abandonment risk.
The package and repository each contain only three files: a README, composer manifest, and implementation file. This is easy to inspect, but it also provides little evidence of testing or mature project practices.
The repository name matches the package, supporting the link, but its README does not mention the package name. That weakens repository-to-package traceability slightly.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no community signal to offset the lack of maintenance activity.
Composer is used for builds, but no security scanning tools are present. The missing scanning is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.