The package has a clear README, an MIT declaration, and only two runtime requirements. Its single maintainer, one-star repository, missing tests and security policy, and more than six years without commits or releases reduce confidence in long-term support.
45%
Total Score
25
100
78
75
The package has only two releases, and its latest release was in April 2020; it has had no releases in the last 12 months. This is strong evidence of abandonment risk, although the stable 1.0.1 version may still suit a narrowly scoped utility.
The repository recorded zero commits and zero active maintainers in the last three months, with the last push in April 2020. The long period without observed maintenance materially lowers confidence in support and compatibility.
Only one registry maintainer is listed, leaving little visible publishing redundancy. The linked repository is also owned by an individual, so no organizational backing compensates for the thin maintainer base.
The repository has one star, zero forks, and one watcher, providing little external evidence of adoption or community support. Low popularity is supporting evidence only and does not outweigh the package's otherwise clear identity and licensing.
Composer is used for the build, but no security scanning tools are configured. The missing scanning is a modest hygiene gap rather than evidence that the release is unsafe by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.