The package is small and understandable, with a README, no install scripts, and only one runtime dependency. Organization backing and source identification help, but there is no license, security policy, or recent maintenance to support continued dependency use.
12%
Total Score
50
100
42
83
Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning against taking a new dependency on it.
Only two releases exist, both published in April–May 2018, with no releases in the last 12 months. The roughly 8-year release gap is a severe abandonment concern.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with its archived state and providing no evidence of ongoing maintenance.
The linked repository is archived and was last pushed about 8 years ago. Archived source strongly indicates the package is no longer maintained.
Neither the package nor the linked repository has a declared license or license file. That creates a material legal and adoption barrier for a dependency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.