The codebase is small and clearly identified, with an MIT license and no install-time scripts. Maintenance evidence stops in January 2020, with only three releases, one registry maintainer, no tests, and no security policy. Pinning this old release carries meaningful abandonment risk.
42%
Total Score
50
58
75
The latest release was over six years ago, with no releases in the last 12 months and only three releases overall. This is strong evidence of abandonment risk for a dependency that may need updates.
Only one account has registry publish access. The linked repository is user-owned rather than organization-backed, so there is little visible redundancy if that maintainer stops supporting the package.
The repository has zero stars and forks and only one watcher. Popularity is not required for health, but this provides little supporting evidence of adoption or community support.
Composer is used as the build tool, which fits the package, but no security scanning tools are present. This is a hygiene gap that adds to the limited transparency of an otherwise inactive project.
The repository has no security policy. For a small, inactive package this reduces transparency around vulnerability reporting and maintenance expectations.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.