The MIT license, documented release notes, and repository tests improve transparency. Only one contributor is active, and no security policy is published.
12%
Total Score
67
100
57
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on it.
The package has only three releases, with the latest released in July 2019 and none in the last 12 months. That long release gap creates substantial abandonment and compatibility risk.
The linked source repository is archived, which strongly indicates that normal maintenance and issue handling have ended. This outweighs the repository's other positive signals.
All recent commit activity comes from one contributor. Organization ownership may allow handoff, but no second active contributor is shown in this signal.
The repository recorded only one commit in the last three months, from one active maintainer. This is weak evidence of ongoing maintenance, especially alongside the archived status.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.