The package includes tests, documentation, a license file, and no install-time script. Its single-user project has seen no release or repository update for over eight years, while adoption is nearly absent.
42%
Total Score
69
75
The latest release was published over eight years ago, with no releases in the last 12 months. That strongly indicates abandonment risk despite the package having a history of 10 releases.
The repository has 0 stars and 0 forks, with only 1 watcher. Popularity is supporting evidence rather than a verdict, but these values provide no meaningful community-maintenance cushion.
The project uses Composer build tooling, but no security-scanning tool was detected. This is a modest transparency and hygiene gap, not a severe risk by itself.
The repository is not archived, which is mildly reassuring, but its last push was over eight years ago and does not show ongoing maintenance.
The linked repository has no security policy. For an old browser plugin this is a transparency gap, though it does not independently show that the release is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.