Risky to adopt: this package has had only one release, with no new releases or repository commits since November 2021. It is not deprecated or archived, but its six-character README and minimal three-file project provide little evidence of ongoing maintenance or consumer guidance.
42%
Total Score
0
64
75
There has been exactly one release, published in November 2021, and none in the following roughly four years and ten months. This is strong evidence of an unmaintained package rather than a mature release history.
The repository had zero commits and zero active maintainers in the last three months, consistent with the long period since its only release. This materially increases abandonment risk.
The artifact and repository each contain only three files, including a minimal README, composer manifest, and registration file. That may fit a small extension, but it leaves little visible project structure to support confidence in long-term maintenance.
The package includes a README, but it is only six characters long and gives consumers virtually no integration guidance; the absence of tests and a changelog is normal for a published artifact and is not penalized.
Composer is used as a build tool, which is appropriate for a Packagist package, but no security scanning tooling is present. This is a modest transparency gap, not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.