The package has seen no release or repository activity since December 2017, and its source tree is extremely small with no README or tests. The linked repository name does not match the package, which makes ownership and ongoing maintenance less clear.
35%
Total Score
100
56
67
Only two releases were published, both on December 29, 2017, with no releases in the last 12 months. That long period without a new release is strong evidence of abandonment risk.
The repository is not archived, but it was last pushed on December 29, 2017. Its unarchived status does not compensate for nearly nine years without observed source activity.
The package and repository each contain only four files: composer metadata and two source files. This may fit an example project, but it provides little evidence of a mature, actively maintained library.
The artifact has no README, tests, or changelog; missing tests and changelog are normal for published artifacts, but the missing README reduces consumer transparency. A GitHub release exists for this version, which partly compensates for release documentation.
The repository name does not match the package name, and no README mention was found. That mismatch makes it less clear that the linked repository is the intended source for this package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.