Its tiny source tree and missing security policy provide little evidence of ongoing maintenance or review. The package is licensed under MIT, but the repository has not changed in over six years and does not clearly identify this package.
38%
Total Score
0
64
67
Only two releases were published, both in May 2020, with no releases in roughly six years. That strongly suggests the package is abandoned or frozen.
The repository recorded no commits and no active maintainers in the last three months, consistent with its last push being over six years ago. No newer activity compensates for the long maintenance gap.
The package and repository each contain only five files, including no README, tests, or changelog. Such a minimal tree gives consumers little transparency into usage or maintenance, although the license and Composer manifest are present.
The artifact has no README, while tests and a changelog are not expected in published packages; the missing README is a real documentation gap for a library consumers must integrate. No release notes or repository documentation compensate for it.
The linked repository name does not match the package name, and no README mention was collected. This raises concern that the repository may not actually be the package's source, though a subpackage or monorepo could explain the mismatch.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.