Its 0.0.x version and single publisher leave limited maturity and ownership redundancy. The documented release, matching repository, MIT license, and clear README help, but the project has not shown maintenance activity since 2021.
46%
Total Score
25
67
75
The package has had no releases in about five years: four releases total, with none in the last 12 months. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the extended release gap and increasing maintenance risk.
Only one registry publishing account is listed, leaving little visible publishing redundancy. This is more concerning because the repository also shows no recent activity.
Composer build tooling is present, but no security scanning tooling was detected. That is a modest transparency and maintenance gap, not a severe risk by itself.
The linked repository has no security policy, reducing guidance for reporting and handling vulnerabilities. This is a minor transparency gap alongside the broader maintenance concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fightbulc/moment Version ^1.33 | — | — |
react/event-loop Version ^1.1 | — | — |
jolicode/jolinotif Version ^2.3 | — | — |
react/child-process Version ^0.6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.