The MIT license, stable version, and matching organization repository improve transparency. Its tiny consumer-facing documentation and minimal adoption signals leave little support for dependable ongoing maintenance.
42%
Total Score
0
67
50
The package has only one release, published about eight years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the stable 1.0.0 version.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. No newer activity compensates for the maintenance concern.
The artifact includes a README, but it is only 19 characters long, offering almost no integration guidance for a library. Missing tests and a changelog are normal packaging practice and are not counted against it.
The repository has zero stars and forks and one watcher, providing little evidence of active adoption or community support. Popularity is supporting evidence only, so this modestly reinforces rather than determines the assessment.
The linked repository has no security policy. This is a transparency and vulnerability-reporting gap, although it is less severe than the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/pipeline Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.