The package is small, focused, and includes tests, a README, and a matching source repository. Its licensing is undocumented, and the project lacks security tooling or a security policy; adopting it means accepting substantial maintenance risk.
42%
Total Score
50
72
83
This release is the package's only release, published 10 years ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance.
There were no commits or active maintainers in the last 3 months, consistent with a project that has been inactive since its sole release. This is the clearest abandonment concern.
No declared license or license file was detected in the package or repository. This is a transparency and reuse concern for consumers.
Composer build tooling is present, but no security scanning tools were detected. For a small package this is a hygiene gap rather than evidence of maliciousness.
The repository is not marked archived, but its last push was 10 years ago. The non-archived status is reassuring administratively but does not compensate for the lack of recent work.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/composer Version 1.*@beta | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.