Its small dependency footprint, tests, and MIT licensing reduce adoption friction. The repository has been inactive for over three years, and its weak project linkage and missing security practices add maintenance risk.
58%
Total Score
50
100
78
75
There were zero commits and zero active maintainers in the last three months, consistent with the repository's last push in January 2023. This is a substantial abandonment concern for a package assessed more than three years later.
The package has five releases since February 2012, but none in the last 12 months; the latest release was in January 2023. This indicates a long period without published maintenance.
The repository name does not match the package name and its README does not mention the package, so the linkage is less transparent and the repository could be serving a broader or different project.
The repository has six stars, two forks, and one watcher, indicating limited external adoption. Popularity is only supporting evidence, but the small audience provides little additional maintenance assurance.
Composer and Phing build tooling are present, but no security scanning tools were detected. The build structure is useful, while the absence of scanning is a modest transparency gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.