The package is small and has a clear MIT license with no install-time scripts, but it lacks tests, security scanning, and a consumer README. Its source has had no commits or active maintainers for over nine years, making future fixes unlikely.
36%
Total Score
0
67
83
This is the only release, published nearly ten years ago, with no releases in the last 12 months. That strongly raises abandonment risk despite the package not being deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history and suggesting no current maintenance capacity.
The artifact has no README, tests, or changelog, while the repository also reports no tests or changelog. The absence of tests and a changelog is a real maturity gap for a library, and the missing README reduces integration guidance.
Composer is used for the build, but no security scanning tools are present. This is a hygiene gap, though it does not outweigh the much stronger maintenance evidence.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This adds transparency risk to an already inactive project.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.