Usable with caveats: the package is licensed, stable, tested, and has a matching source repository, but its latest release was about eight years ago and the repository has had no recent commits. Avoid it for dependencies requiring active maintenance or timely security response.
62%
Total Score
33
100
88
90
The repository recorded zero commits and zero active maintainers in the last three months, a strong sign that maintenance has stalled despite the repository not being archived.
The registry namespace and repository owner match, providing consistent ownership evidence. The owner is an individual rather than an organization, so the single-person backing offers limited maintenance redundancy.
The project has 22 releases over its lifetime, but its latest release was about eight years ago and there were no releases in the last year, indicating substantial release inactivity.
There are open issues and pull requests, but none were opened, closed, or merged in the last month, providing no evidence of active issue handling.
Composer is used for the build, but no security scanning tools are configured. For a small, older PHP library this is a hygiene gap rather than evidence that the package is unfit by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.