Its small footprint, MIT license, and organization backing make the package straightforward to inspect. However, maintenance appears to have stopped, with no releases or commits for over eight years and no security policy. Treat this release as a risky dependency.
34%
Total Score
50
57
75
The package has had no release in over eight years: its latest release was February 14, 2018, despite only five total releases. This is strong evidence of abandonment for a framework helper library.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. No provided maintenance signal compensates for this inactivity.
A README is present, which supports basic consumer understanding, and the absence of tests or a changelog is normal for published artifacts. The repository also has no tests or changelog, leaving maintenance evidence thin but not decisive by itself.
The repository has zero stars and zero forks, with four watchers. Popularity is only supporting evidence, but these numbers provide no community-maintenance buffer for an otherwise inactive project.
Composer is used for the build, but no security-scanning tooling is present. This is a modest transparency and maintenance gap rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.