The package is small and clearly mapped to its repository, with an MIT declaration and no install-time scripts. There is little evidence of ongoing care or security review, so pinning this old release carries maintenance risk.
38%
Total Score
0
72
75
This is the package's only release, published four years and nearly six months ago, with no releases in the last 12 months. That strongly limits evidence of continued maintenance.
The repository has recorded no commits and no active maintainers in the last three months, consistent with the release history's long period of inactivity.
The artifact has no README, tests, or changelog, but the source repository also shows no tests or changelog; the GitHub release flag is positive for release traceability. The missing consumer documentation is a minor concern, not an abandonment signal.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide no meaningful external maintenance signal.
Composer is used as the build tool, which is appropriate, but no security-scanning tools are present. The missing scanning is a modest review gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.