42%
Total Score
unhealthy
Risky: no release or commit activity since 2019 points to a likely abandoned package.
There were zero commits and zero active maintainers in the last 3 months, consistent with the repository last being pushed about 7 years ago. This materially increases abandonment risk.
A README is present, but it is only 82 characters and provides very little consumer guidance. Missing tests and a changelog are normal for a published package artifact, so they are not treated as gaps here.
Only two releases were published, with the latest about 7 years ago and none in the last 12 months. That long release gap is strong evidence of abandonment risk, although the package is not marked deprecated.
The repository name does not match the package name and its README does not mention the package. That weakens confidence that the linked repository is the authoritative source for this release.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are reported. The missing scanning is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.