Its single dependency and lack of install-time scripts reduce operational risk. The project has seen no commits or releases since March 2017, and the three-file repository provides little documentation or development support.
38%
Total Score
50
100
50
75
This is the package's only release, published about nine years ago, with no releases in the last 12 months. That is strong evidence of a dormant project, even for a small package.
There were zero commits and zero active maintainers in the last three months, consistent with the last push occurring in March 2017. This is the strongest abandonment indicator in the collected evidence.
The artifact and repository each contain only .gitignore, composer.json, and one PHP file. This may be adequate for a tiny utility, but it leaves little evidence of testing, documentation, or ongoing project support.
The package has no README, while tests and a changelog are normally expected in the source repository rather than the published artifact; the GitHub release itself is a small positive. The missing consumer documentation still weakens transparency for a library.
The repository name does not exactly match the package name, but the package appears to be a sub-package-style project under an organization; no README was available to confirm the relationship. This creates a modest ownership and traceability concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.