The project has a clear MIT license, a readable README, and a very small dependency footprint. Its minimal source base has no security policy or scanning support, leaving limited evidence that future maintenance and vulnerability handling are active.
35%
Total Score
25
100
81
75
The latest of only three releases was published in April 2015, with no releases in the past 12 months. That long gap is strong evidence of abandonment risk, although the package is not registry-deprecated.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the release history showing no meaningful maintenance since 2015.
Only one registry publishing account is listed, so there is little visible publishing redundancy. The linked repository is user-owned rather than organization-backed, which provides no compensating maintainer capacity.
Composer is used for builds, but no security scanning tools are present. That reduces evidence of ongoing dependency and release hygiene.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency and maintenance concern, not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.