Documentation is minimal, and the project has no tests or security scanning. Its small dependency footprint and matching source repository reduce integration and provenance concerns.
38%
Total Score
25
100
63
83
Only two releases were published, with the latest in March 2019 and none in the last 12 months. This long period without releases is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months. Combined with the last push being in March 2019, this indicates no observable ongoing maintenance.
The package is backed by an individual repository owner rather than an organization, so the lack of observable maintainer or contributor activity is more concerning than it would be for an organization-backed project.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no additional community or adoption signal to offset the maintenance concerns.
Composer is used as a build tool, but no security scanning tooling is present. The missing scanning is a modest transparency and maintenance gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.