The linked repository has no recent commits and does not identify this package in its name or README. Licensing, documentation, and the absence of install-time scripts are otherwise reassuring, but they do not offset the maintenance and provenance concerns.
14%
Total Score
0
100
58
75
Packagist marks the entire package as abandoned, with no replacement identified beyond the same package name. Package-level deprecation is a severe adoption risk because future maintenance is not expected.
The package has 20 releases since June 2015 but none in the last 12 months; its latest release was in September 2019, roughly 7 years ago. This strongly indicates abandonment for a dependency that may need framework compatibility updates.
The repository recorded zero commits and zero active maintainers in the last 3 months. This supports the release-history evidence of inactive maintenance rather than merely an irregular release schedule.
The repository name does not match the package name, and its README does not mention this package. That raises provenance concerns because the linked repository may not actually be the package's source.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, adding concern to an already inactive project.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.