Its README and tests make the package understandable, and its dependency footprint is small. The organization-backed repository is not archived, but it does not clearly identify this package, which reduces confidence in its provenance.
38%
Total Score
100
100
57
50
The package has only two releases, both in December 2016, with no release in over 9 years. That strongly indicates abandonment risk despite the initially short four-day release interval.
A post-update Composer script is present. This is not inherently unsafe, but it adds install/update behavior that should be understood when adopting an otherwise old package.
The repository name does not match the package name and its README does not mention the package. A monorepo mismatch can be normal, but the lack of any package reference makes the source association less clear.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counts provide little evidence of a broad maintenance or user community.
Composer build tooling is present, but no security-scanning tooling is reported. For this small, old package that is a modest transparency gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.