The minimal dependency surface and repository tests offer limited reassurance. Its lack of a security policy, missing README, and single registry maintainer leave little transparency or resilience for future compatibility work.
12%
Total Score
25
100
42
50
Packagist marks the entire package as abandoned, with no replacement specified. That is a direct warning against taking a new dependency on this release.
The package has had no release in about 12 years and no releases in the last 12 months. This strongly indicates abandonment rather than a merely slow release cadence.
There were zero commits and zero active maintainers in the last three months, consistent with the repository's archived state and leaving no evidence of ongoing maintenance.
The linked repository is archived and was last pushed about 12 years ago, indicating the source project is no longer maintained.
Only one registry account has publish access. Organization backing is present, but the archived repository and absent recent activity provide no evidence of an active maintainer base.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.