The code is small and tested, with no runtime dependencies. Licensing is clear and installation is uneventful, but the package offers little consumer documentation and its age leaves compatibility uncertain.
42%
Total Score
50
100
57
75
This package has made only one release, on August 5, 2016, with no releases in the last 12 months. That strongly indicates abandonment risk for a dependency.
There were no commits and no active maintainers in the last three months, consistent with a project that has been inactive for years.
The package includes tests in both the artifact and repository, which is positive, but it has no README and no changelog. The missing README is a real consumer-documentation gap for a library.
Composer is used for the build, but no security scanning tooling is present. This is a modest transparency and maintenance gap, not a standalone reason to reject a small package.
The repository is not archived, which preserves a path for maintenance, but it was last pushed on October 14, 2016. The absence of recent repository activity reinforces the age concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.