The repository contains substantial source code, documentation, tests, and a changelog, while the MIT licensing and lack of install scripts reduce adoption friction. Its single-person ownership, negligible usage signals, absent security policy, and fully unpinned workflow actions leave maintenance and build-integrity concerns.
48%
Total Score
25
70
75
The package has had no release in over three years and none in the last 12 months, despite four releases clustered at its initial publication. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of ongoing maintenance to offset the stale release history.
One registry maintainer is consistent with a small project, but it leaves little visible publishing redundancy when combined with the lack of recent releases and commits.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these values provide no external sign of adoption or community support.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, although it is less severe than the maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phplang/scope-exit Version ^1.0 | — | — |
swaggest/json-diff Version ^3.8.2 | — | — |
symfony/polyfill-mbstring Version ^1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.