Usable with caveats: the package is small, clearly licensed, tested, and its repository matches the package, but it has had no release or commit activity for over seven years. Depend on it only if its stable, narrow functionality fits your needs and you can accept limited ongoing maintenance.
58%
Total Score
50
100
79
88
The package has only three releases and none in the last 12 months; its latest release was published over eight years ago. This is a significant maintenance concern, although the stable major version reduces release-churn risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release. This weakens confidence that defects or compatibility issues will be addressed.
Composer is used as a build tool, showing basic project tooling, but no security scanning tools are configured. For this small library the missing scanning is a hygiene gap, not a severe risk.
The repository is not archived, which avoids the severe abandonment signal, but its last push was over seven years ago. The inactive history still indicates limited current maintenance.
The repository has no security policy. This reduces transparency for reporting vulnerabilities, though it is less consequential for a small, narrow library than for a security-sensitive service.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.