The package has no declared or detected license, and its two-file artifact offers little consumer documentation. Organization backing and a simple dependency/install setup do not offset over nine years without maintenance; pinning this old release is risky.
35%
Total Score
50
100
60
83
Only one release was published, on 17 February 2017, with none in the last 12 months; this is strong evidence of abandonment risk.
The repository had zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity for over nine years.
Neither the package nor the linked repository declares or contains a recognized license, leaving reuse and redistribution terms unclear.
The artifact contains only the PHP file and composer.json, which is consistent with a very small plugin but provides little visible context for consumers.
The linked repository is not formally archived, although its last push in February 2017 confirms that the absence of an archive flag does not indicate active maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.