The small, tested codebase has clear documentation and a narrow dependency surface. Its long-standing inactivity and mismatch between the assessed v2.0.0 and the recorded latest v1.2.1 leave maintenance and release provenance uncertain.
30%
Total Score
25
100
63
83
The package has had no releases in roughly 11 years and none in the last 12 months, which is strong evidence of abandonment for a dependency. Its six historical releases show it was once published, but do not compensate for the prolonged inactivity.
The repository has had zero commits and zero active maintainers in the last three months, consistent with the long release hiatus. The repository is not archived, but that does not compensate for absent recent development.
There has been no issue or pull-request activity in the last month. With no recent release or commit activity to show maintenance elsewhere, this supports concern about project abandonment.
The repository has zero stars and forks and only one watcher. Popularity is not required for health, but these figures provide no supporting evidence of an active user or contributor community.
Composer is used for the build, which fits the package, but no security-scanning tooling is present. This is a transparency and maintenance gap rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.