The four-file artifact is easy to inspect, clearly licensed, and has no install-time scripts. It has no security policy or security scanning, leaving little evidence of ongoing assurance.
12%
Total Score
0
42
75
Packagist marks the package as abandoned at package scope, with no replacement provided. This is a direct warning against taking a new dependency on this release.
Only two releases exist, with none in the last 12 months; the latest release was published in May 2018. This shows no recent release maintenance.
The repository had zero commits and zero active maintainers in the last three months. Together with the archived state, this indicates no ongoing development capacity.
The linked repository is archived, and its last push was in May 2018. An archived source project is a severe abandonment risk for a dependency.
Composer is used as a build tool, but no security scanning tools are reported. The missing scanning is a modest hygiene gap rather than evidence of maliciousness or a standalone health verdict.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.