The package has a clear README, an MIT declaration, and only one runtime dependency. It lacks tests and security tooling, so maintenance changes would be hard to validate.
42%
Total Score
0
100
67
75
Only two releases were published, both on January 28, 2016, with no releases in the last 12 months. That long release gap is strong evidence of abandonment risk, despite the package not being deprecated.
The repository has had zero commits and zero active maintainers in the last three months, after last being pushed in January 2016. This indicates that defects and compatibility issues are unlikely to receive attention.
Composer is used for the build, providing basic project tooling, but no security scanning tools are configured. For a package handling an API key, that leaves a meaningful validation gap.
The repository is not marked archived, which is a compensating positive, but its last push was in January 2016. The inactive repository still creates a substantial maintenance concern.
The repository has no security policy. This reduces transparency about how vulnerabilities should be reported, although the absence is less significant than the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.