The MIT license, README, release notes, and matching source repository make the package transparent and straightforward to inspect. Its single-maintainer project also lacks security scanning and a security policy, adding maintenance risk.
43%
Total Score
50
100
81
83
The latest release was published about 6 years and 3 months ago, with no releases in the last 12 months; this is strong evidence that maintenance has stopped.
There were no commits or active maintainers in the last 3 months, consistent with the long gap since the last repository push and raising abandonment risk.
There is one open issue and no issue or pull-request activity in the last month, providing no evidence of current project response.
Composer is used as the build tool, which is appropriate for this package, but no security scanning tools were detected; this is a modest transparency and maintenance gap.
The repository is not archived, but it was last pushed about 6 years and 3 months ago, so the active status does not offset the stale source history.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.