This is a small, mature Packagist package with a stable major version, an MIT manifest license, minimal runtime dependencies, no install-time lifecycle scripts, and no registry deprecation. However, transparency and maintenance evidence are limited: no source repository is declared, the artifact contains no tests or separate changelog, and only one release was published in the last 12 months despite the package being over 10 years old. It may be usable, but adopting it carries moderate maintenance and verification risk because repository activity and broader project backing cannot be assessed.
62%
Total Score
100
80
100
A 2,607-character README is present and includes a historical changelog, but the artifact has no tests and no separate changelog. With no repository evidence available to compensate, this is a genuine verification and maintenance gap.
The package has existed for 3,774 days with 25 releases, but only one release occurred in the last 12 months. This indicates a long release history with currently limited visible release activity, which warrants maintenance caution.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.