The MIT declaration, matching repository, and published README provide basic transparency. However, the package has no recent maintenance or security policy, so adopting it would leave a project dependent on abandoned software.
12%
Total Score
0
56
75
Packagist marks the entire package as abandoned. With no replacement supplied, this is a direct warning against taking a new dependency on it.
Only six releases were published, with the latest on June 30, 2017 and none in the last 12 months. This indicates long-term abandonment rather than an actively maintained release line.
There were zero commits and zero active maintainers in the last three months, consistent with the repository being abandoned for over nine years.
The linked repository is archived and was last pushed on June 30, 2017, confirming that active project maintenance has ended.
Composer is used for project tooling, but no security scanning tools are present. This is a modest transparency and maintenance weakness, secondary to the abandonment evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.