Risky to adopt: the last release and repository update were in December 2015, with no commits in the past three months. The package is small and dependency-light, but it has no discovered license and shows little evidence of ongoing maintenance.
42%
Total Score
0
50
83
The package has only three releases and none in the past 12 months; its latest release was in December 2015, indicating roughly ten years without a new release. This is a substantial abandonment risk despite the package's age and potentially stable scope.
There were zero commits and zero active maintainers in the past three months. For a dependency last released roughly ten years ago, this strongly suggests maintenance has stopped.
No declared license or license file was found in the package or repository. That creates a real adoption and legal-transparency concern for an open-source dependency.
The repository has only two stars and no forks, providing little evidence of a broad user or contributor community. Popularity is supporting evidence rather than decisive, but it offers no compensating maintenance signal.
Composer is used as a build tool, which fits the package's ecosystem, but no security-scanning tools are configured. The missing scanning is a hygiene gap, though it is less significant than the long-term inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.