The package has a clear MIT license, a consumer README, and organization backing. However, its last release and repository push were about 10 years ago, with no recent commits, making compatibility and maintenance uncertain.
42%
Total Score
50
78
75
The package has had no release in about 10 years, despite six historical releases. This is strong evidence of abandonment risk for a dependency that may need compatibility updates.
There were zero commits and zero active maintainers in the last three months, consistent with the last repository push being about 10 years ago. This materially increases abandonment risk.
The repository has zero stars, one fork, and two watchers. Popularity is only supporting evidence, but these very low counts provide little external evidence of active use or review.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance concern, not a severe risk by itself.
The repository has no security policy. For a small, old plugin this limits vulnerability-reporting transparency, although it is less significant than the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.