The MIT declaration and matching repository name provide basic transparency, and installation has no lifecycle scripts. Documentation is only a 10-character README, while the repository has no security policy or security scanning.
32%
Total Score
0
63
50
The package has only one release, published about eight years ago, with no releases in the last 12 months. This strongly suggests abandonment rather than an actively maintained dependency.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long-standing lack of releases and indicating no current maintenance activity.
The package includes a README, but it is only 10 characters long, offering very little guidance for consumers. The absence of tests and a changelog in the published artifact is normal packaging practice, and the GitHub release is a positive transparency signal.
The repository has zero stars and forks and only one watcher, providing little supporting evidence of community adoption. Low popularity alone is not decisive, but it reinforces the thin project maturity indicated elsewhere.
The repository uses Composer, which is appropriate for a Packagist package, but no security scanning tools are present. The build tooling is a small positive while the missing scanning is a minor hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.