Clear documentation, tests, licensing, and a matching source repository make the package easy to inspect and integrate. Its lone maintainer, absent recent commits, and unpinned workflow actions reduce confidence in continued upkeep.
38%
Total Score
50
100
71
67
Packagist marks the entire package as abandoned, with no distinct replacement, which is a major warning for continued maintenance and dependency safety.
One registry publishing account supports a thin maintainer base, although the repository is owned by the same individual, so this is a modest resilience concern rather than a standalone severe risk.
The package has 44 releases over more than 13 years, but none in the last 12 months; the long gap indicates that maintenance has stopped or sharply slowed.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the abandonment concern rather than showing active upkeep.
There were no new or closed issues or pull requests in the last month, with eight issues still open, providing no evidence of current project attention.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.