Tests are present, and the repository remains unarchived with organization backing. However, this release has no license and the project has shown no release or commit activity for roughly nine years, making long-term maintenance and adoption risky.
38%
Total Score
50
50
50
Neither the package metadata nor the package or repository contains a recognized license. That creates a significant legal and adoption obstacle for dependents.
The package has only one release, published roughly ten years ago, with no releases in the last 12 months. This strongly indicates a stagnant release process.
The repository recorded no commits or active maintainers in the last three months, consistent with the long gap since its last push and indicating substantial abandonment risk.
Composer is used as a build tool, but no security scanning tools are present. The missing scanning is a hygiene gap rather than evidence of abandonment on its own.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This adds a smaller concern alongside the stronger maintenance and licensing problems.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.