The package is small, clearly tied to its intended repository, and backed by an organization. Its last release and repository push were over eight years ago, with no recent commits, so maintenance and compatibility risk are substantial.
38%
Total Score
50
58
50
The package has only two releases, with the latest published over eight years ago and none in the last 12 months. This is strong evidence of abandonment risk for a dependency.
There were zero commits and zero active maintainers in the last three months, consistent with the repository having received no updates since February 2018.
Composer is used for the build, but no security scanning tools are present. This is a hygiene gap rather than evidence that the package is unsafe on its own.
The repository is not archived, which avoids an explicit abandonment marker, but it was last pushed at the same time as the stale release history.
The repository has no security policy, reducing transparency for reporting and handling issues. The small, inactive project provides no compensating security process in the collected evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.