The tiny source tree and minimal activity suggest limited ongoing maintenance capacity. The package has a declared MIT license and no install-time scripts, but its repository does not clearly identify the package and has seen no commits for about 10 years.
28%
Total Score
0
50
67
All three releases arrived within about two hours in April 2016, and there have been no releases in about 10 years. That strongly suggests the package is abandoned rather than actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months, with its last push in April 2016. This is strong evidence that maintenance has stopped.
The published artifact contains only composer.json and one PHP file, while the repository contains only those files plus a README. This is a very small implementation with little supporting project material.
The linked repository name does not match the package name, and its README does not mention the package. That weakens confidence that the source repository clearly belongs to this release.
The repository has no security policy. For a small, inactive library this adds a transparency gap, although it is less significant than the lack of maintenance evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.