The repository is not archived, and the package includes tests and a matching MIT license. However, its source has not been pushed since March 2018, and the repository does not name or mention this package, which weakens confidence in ongoing support.
38%
Total Score
50
63
75
The package has only one release, published in May 2016, with no releases in the last 12 months; this is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months, consistent with a project that has seen no recent maintenance.
The repository name does not match the package name and its README does not mention the package, so the linkage is not clearly demonstrated and may reflect a repository mismatch.
The repository uses Composer, but it has no security scanning tools; this is a modest transparency and maintenance gap rather than a severe risk on its own.
The linked repository is not archived, but its last push was in March 2018, so the non-archived status offers little compensation for its age.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.