The package is clearly identified, licensed, and lightweight, with no install-time scripts or registry deprecation. Its one-release history and roughly 11 years without commits make long-term maintenance and compatibility a serious concern.
34%
Total Score
50
70
75
The package has only one release, published about 11 years ago, with no releases in the last 12 months. This is strong evidence of a dormant release line, despite the package not being deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the roughly 11-year-old release and indicating no observed ongoing maintenance.
Only one registry account has publish access. Organization backing provides some context, but the registry still shows a very thin publishing base for a package with no recent releases.
Composer is used for builds, but no security scanning tooling is present. This is a hygiene gap, though it is secondary to the much stronger evidence of inactivity.
The repository has no security policy. That weakens disclosure transparency, but it is a supporting concern rather than the primary reason this release is risky.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.