The package is clearly identified, MIT-licensed, and includes a usable README and release changelog. Its very small project footprint, absent security process, and lack of recent maintenance make long-term support uncertain.
42%
Total Score
50
100
72
88
The package has had no release in the last 12 months, and its latest release was about 5 years ago despite 13 total releases. This strongly lowers confidence that current issues will be addressed.
There were zero commits and zero active maintainers in the last 3 months, consistent with a project that has stopped receiving maintenance.
The repository has 1 star and no forks or watchers, offering little supporting evidence of broad review or an active user community. Popularity is supporting evidence, but this reinforces the maintenance concern.
Composer build tooling is present, but no security scanning tools are configured. This is a modest transparency and maintenance gap rather than a standalone severe risk.
The linked repository is not archived, but its last push was about 5 years ago. The active archive status is mildly reassuring while the old activity remains concerning.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.