The package is well documented, licensed, and has a very small dependency footprint. Its source has seen no commits or active maintainers for over six years, with little adoption and no security policy, so future compatibility and maintenance are uncertain.
48%
Total Score
25
100
78
83
The package has had only four releases, all clustered in January 2020, with no releases in the last 12 months and no later release activity. This is strong evidence of abandonment for a library consumers may need to keep compatible.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the last push occurring in January 2020. No provided maintenance signal compensates for this prolonged inactivity.
The repository is owned by the same individual namespace as the package, providing consistent ownership context. It does not provide organization-level backing or evidence of a broader maintenance team.
The repository has 1 star, 1 fork, and 0 watchers, indicating very limited adoption and little visible community support. Popularity is supporting evidence rather than decisive on its own, but it reinforces the maintenance concern.
The repository uses Composer build tooling, but no security scanning tools are reported. The missing scanning is a modest hygiene gap rather than a standalone dependency risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.