It has a clear MIT license, a useful README, and organization backing. The release is from 2015, with no releases in the past 12 months and no commits or active maintainers in the past three months. The repository lacks a security policy and security scanning, so pinning this version carries substantial maintenance risk.
38%
Total Score
50
75
50
The latest release was published in December 2015, and there have been no releases in the past 12 months. This is strong evidence of abandonment for a package intended as a reusable extension.
The repository recorded zero commits and zero active maintainers during the past three months. Combined with the old latest release, this indicates a severe abandonment risk.
There are two open issues, but no issues or pull requests were opened or closed in the past month. This supports the broader evidence of inactive maintenance.
The repository uses Composer, which supports reproducible package management, but it reports no security scanning tooling. That is a modest transparency and maintenance gap for a dependency.
The repository is not archived, but it was last pushed in September 2020. The non-archived status is positive, while the old push date is consistent with the maintenance concerns shown by release and commit activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.