Documentation and licensing are present, and installation does not run lifecycle scripts. The project has shown no commits or releases for about five years, while security scanning and a security policy are absent.
43%
Total Score
0
100
81
75
The package has had only 3 releases, all clustered in October 2021, with no releases in about five years. That long gap is strong evidence of abandonment risk despite the stable 1.0.3 version.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with the roughly five-year release gap. This materially increases the chance that bugs and compatibility issues will remain unresolved.
Composer is used for the build, but no security-scanning tools were found. That is a transparency and maintenance weakness, though it is less serious than the project's prolonged inactivity.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This adds a transparency gap for a package intended for application use.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.