It has a clear BSD-3-Clause license, a README, tests, and no install-time scripts. The repository directly references the package, but its small footprint and limited project hygiene provide little additional reassurance.
35%
Total Score
0
100
78
83
The package has only one release, published nearly 13 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a dependency intended for ongoing use.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap and leaving no evidence of current maintenance.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but it provides no meaningful community signal to offset the inactivity.
Composer is used as a build tool, providing basic project tooling, but no security scanning tools are present. This is a minor hygiene gap and does not outweigh the maintenance concerns.
The repository has no security policy. For this small, inactive package this is a transparency gap, though it is less significant than the long-standing lack of releases and commits.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.