A readable README, declared license, and no install-time scripts make the package straightforward to inspect and add. The source has no security policy or scanning, leaving limited evidence of ongoing project care.
39%
Total Score
50
63
50
This package has only one release, published nearly eight years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers over the last three months, providing no evidence of current maintenance capacity.
The repository has 0 stars and 0 forks, with only 1 watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little additional confidence in the project’s maturity or support.
Composer is used for builds, which is positive, but no security-scanning tooling was detected. The missing scanning is a modest hygiene gap alongside the broader lack of maintenance evidence.
The repository has no security policy, which reduces transparency for reporting and handling defects. This is a maintenance and process gap, not evidence that the package is malicious.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.