The MIT license and matching repository make the package transparent, but its minimal four-file project offers little evidence of testing or security practice. Pinning this sole release leaves you dependent on a project with no activity since September 2017.
40%
Total Score
33
100
72
67
This package has only one release, published over nine years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a dependency that may need compatibility or security fixes.
There were zero commits and zero active maintainers during the last three months, matching the repository’s last push in 2017. This is the clearest maintenance and abandonment concern.
The artifact and repository each contain only four files, including one source file and no test suite. This very small surface may be appropriate for an adapter, but it provides limited evidence of maturity and maintenance discipline.
The package and repository are owned by the same individual account rather than an organization. Combined with one registry maintainer and no recent activity, this indicates limited visible backing for recovery or continued maintenance.
One issue remains open, while there has been no issue or pull-request activity in the last month. This is consistent with a project receiving no recent maintenance attention.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version >=6.0 | — | — |
league/flysystem-webdav Version >=1.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.