Stable versioning and no install-time scripts reduce day-to-day risk. The tiny project has no security policy and no observable adoption, so future fixes and support are uncertain.
38%
Total Score
75
75
Neither the package nor the linked repository declares or includes a license. Developers therefore lack clear permission to use, modify, or redistribute this dependency.
The latest release was nearly 6 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk despite the package having seven releases overall.
The repository has 0 stars, 0 forks, and 1 watcher, providing no meaningful community or adoption signal to offset the stale release history.
Composer is used for builds, but no security-scanning tools are present. For a small, inactive package this leaves limited evidence of ongoing dependency or code oversight.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. This compounds the lack of visible maintenance activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.