The small artifact is easy to inspect and has a clear README, examples, and a BSD-3-Clause license. Its single-maintainer structure and lack of security tooling provide little confidence for a library without active support.
8%
Total Score
33
100
50
88
Packagist marks the entire package as abandoned, with no replacement identified. This directly indicates that new dependents should not expect supported maintenance.
The package has only one release, 1.0.0, published in May 2015, with no releases in the last 12 months. This supports the abandonment concern rather than showing an active release process.
The repository recorded zero commits and zero active maintainers in the last three months. Together with the archived status, this shows no current maintenance capacity.
The linked repository is archived and was last pushed in May 2015, so the source is no longer actively maintained. This is a severe abandonment risk for a library dependency.
The registry and repository are owned by the same individual account. This is consistent ownership, but it provides no organizational backing to offset the lack of activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.