The package includes a readable guide, tests, and a declared Apache license. Its organization-backed repository is not archived, but the lack of security policy and build security scanning leaves limited transparency for a dependency this old.
38%
Total Score
75
58
50
The package has only one release, published over 12 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk and is not offset by the repository merely remaining available.
There were no new or merged pull requests and no issue activity in the last month, consistent with the very old release history. The open-issues count is unknown, so this is supporting rather than conclusive evidence.
The project uses Make and Composer, showing some build structure, but no security scanning tools were detected. That leaves a modest verification gap for a dependency with no recent activity.
The repository is not archived, which preserves a basic maintenance path, but it was last pushed over 12 years ago. That status does not compensate for the long period without activity.
The repository has no security policy, reducing transparency for reporting and handling dependency issues. This is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.