The repository has no security policy, and one person controls publishing. It does include a README, tests, and an MIT license in the repository, but the package’s long inactivity makes ongoing compatibility uncertain.
36%
Total Score
50
75
50
Only two releases were published, with the latest in March 2014 and none in the last 12 months. That long release silence is strong evidence of abandonment risk.
Registry publishing has one maintainer. A single maintainer is a modest continuity risk for an independently owned project, especially alongside the absence of recent activity.
The linked repository has no security policy. This reduces transparency for reporting and handling vulnerabilities, though it is a secondary concern for this small package.
Version 0.2 is not a stable major release, and the package has only two recorded releases. This reinforces its immature and aging status.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/fractal Version 0.7.* | — | — |
illuminate/support Version 4.2.*@dev | — | — |
symfony/http-foundation Version 2.4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.