The small artifact includes a README, release notes, and no install scripts, keeping adoption straightforward. Composer is present, but the project offers little evidence of support capacity or security oversight.
42%
Total Score
33
100
64
83
This is a single-release package, with no releases in about seven years. That strongly raises abandonment risk, although the package is not marked deprecated.
The repository had no commits and no active maintainers in the last three months. Combined with the old release, this is strong evidence that maintenance has stopped.
Only one registry account has publish access. This is a limited publishing base, and no organizational backing is shown to compensate for that concentration.
The repository is owned by an individual user rather than an organization, and no broader project backing is shown. That provides limited assurance of continuity for a single-maintainer package.
Composer build tooling is present, but no security scanning tool is configured. This is a modest transparency and maintenance gap rather than a standalone reason to reject the package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.