The package has clear licensing, a matching repository, and a small readable artifact. Its single-maintainer project has had no release or commit activity for over 12 years, with no security policy or scanning.
38%
Total Score
25
70
50
The latest release was published in March 2014, and there have been no releases in over 12 years. This is strong evidence of abandonment for a dependency that may need compatibility updates.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its last push being over 12 years ago. No newer activity compensates for this prolonged inactivity.
Only one registry maintainer is listed, which leaves limited visible publishing capacity. The linked repository is user-owned, so the small maintainer base remains a genuine continuity concern.
Composer is used for the project build, but no security scanning tooling is present. The missing scanning is a hygiene gap for a dependency, not evidence of a security incident.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap, though it is less serious than the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.