It includes a clear MIT license, tests, release notes, a substantial README, and a matching source repository. Its tiny user base, absent security policy, and long inactivity make future fixes and support uncertain.
42%
Total Score
50
100
72
75
The package has had no release in more than seven years: its latest of three releases was published in December 2018. That is strong evidence of abandonment for a dependency that may need compatibility updates.
There were zero commits and zero active maintainers in the last three months. Combined with the old latest release, this indicates that compatibility fixes are unlikely to arrive.
There are no open issues or pull requests and no activity in the past month. This is consistent with a quiet project, though it does not by itself prove abandonment.
The repository has only 6 stars and no forks, indicating a small support and review community. Popularity is supporting evidence, so this is a modest concern rather than a decisive failure.
Composer is used as the build tool, but no security-scanning tool is configured. That is a hygiene gap, not proof that the release is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.