The codebase is small, licensed, tested, and has no install-time scripts or declared deprecation. Its lack of security tooling and single-person ownership add modest uncertainty, but the long period without activity is the main concern.
35%
Total Score
25
100
75
83
The package has had no releases in more than 11 years, despite six releases overall. This strongly indicates abandonment risk for a dependency whose fixes and compatibility updates may be needed.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the last push occurring in June 2015. There is no observed recent maintenance to compensate for the stale release history.
Only one registry account has publish access. This is a thin maintainer base and increases continuity risk, although the repository is user-owned rather than organization-backed.
The repository has 0 stars and 0 forks, with only 1 watcher. Popularity is supporting evidence rather than a verdict, but these values provide little evidence of community review or replacement maintenance.
The project uses Make and Composer, which supports reproducible project tasks, but it has no reported security scanning. That is a modest transparency and maintenance gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.