The repository has tests, a changelog, a matching README, and a clear MIT license. It has no security scanning and only one registry maintainer, leaving limited evidence of ongoing care.
56%
Total Score
25
100
78
75
The package has had no release in more than seven years, despite five releases concentrated in March 2019. That strongly limits evidence of current maintenance.
There were no commits and no active maintainers in the three months measured. Combined with the old release history, this is meaningful abandonment risk.
Only one account has registry publish access. The linked repository is user-owned rather than organization-backed, so there is limited visible publishing redundancy.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but these figures provide little supporting evidence of broad community use.
Composer build tooling is present, but no security scanning tools were detected. This is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.