The repository has little documentation or security process, which limits maintenance visibility. Its license, matching source tree, build configuration, and GitHub release provide some provenance, but this old inactive codebase is a poor default dependency.
38%
Total Score
25
75
83
The latest release was in May 2018, with no releases in the past 12 months despite 15 releases overall. This indicates prolonged abandonment risk.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the release history showing no activity for about eight years.
The package has no README, tests, or changelog, reducing consumer guidance and verification. The exact version does have a GitHub release, and the absence of tests or a changelog is otherwise normal for published artifacts.
The source repository is owned by an individual user rather than an organization, so the small visible project backing does not provide additional maintenance capacity.
Composer build tooling is present, but no security-scanning tools are configured. This is a modest hygiene gap rather than evidence of abandonment by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.