Its MIT license, focused README, and matching organization repository provide clear ownership and basic installation guidance. The small artifact has no install-time scripts, but it lacks a security policy and security scanning.
42%
Total Score
50
78
75
The latest release was published over nine years ago, with no releases in the past year. That long gap is strong evidence of abandonment for a package still intended as a dependency.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the release history showing that development stopped over nine years ago.
The repository has zero stars, three forks, and one watcher, providing little supporting evidence of active community use or review. Popularity is secondary, but it does not offset the lack of recent maintenance.
Composer is used as the build tool, but no security scanning tools are configured. This is a modest supply-chain hygiene gap rather than evidence that the release is unsafe.
No repository security policy was found. For a small legacy package this is a transparency gap, though it is less significant than the absence of current maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.