The README, release notes, and minimal runtime dependency make the package straightforward to understand and install. Maintenance has stopped, and the project offers little evidence of ongoing security or contributor support.
12%
Total Score
0
100
33
83
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because the registry itself indicates the package should no longer be depended on.
The package has had 6 releases since March 2019 but none in the last 12 months; its latest release was in October 2020. This indicates prolonged inactivity rather than an actively maintained release line.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with its archived state. There is no observed recent activity to offset the maintenance concern.
The linked repository is archived, and its last push was in September 2022. An archived source project is no longer maintained and strongly increases abandonment risk.
The repository name matches the package, which supports the repository link, but the README does not mention the exact package name. That weakens package-to-repository transparency slightly.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.