Recent releases, tests, and release notes show active maintenance, but the single-maintainer project has limited redundancy and no security policy. The registry marks the package abandoned, so choose a maintained alternative or confirm the abandonment status before adoption.
20%
Total Score
60
100
78
75
Packagist marks the entire package as abandoned, with no distinct replacement identified. This is a severe adoption risk even though other signals show recent maintenance.
One registry maintainer is consistent with the individually owned repository, but it reinforces the limited operational redundancy.
The repository is owned by an individual user rather than an organization, so the single-maintainer and bus-factor concerns are not offset by visible organizational backing.
All recent commits come from one contributor, leaving no demonstrated contributor redundancy for ongoing maintenance.
One commit from one active maintainer in the last three months shows recent activity, but the very low volume provides only modest maintenance evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.