The package has clear licensing, useful documentation, and organization-backed source code. Its prerelease status and long absence of registry releases or recent commits make this version a poor long-term dependency choice.
43%
Total Score
50
100
71
75
Only two releases exist, with none in the last 12 months; the latest registry release is over 10 years old. This is strong evidence of abandonment risk despite the package not being deprecated.
There were zero commits and zero active maintainers in the last three months. Combined with the old latest registry release, this indicates severely limited current maintenance.
There were no new or closed issues or pull requests in the last month, while 54 issues and 18 pull requests remain open. This suggests unresolved maintenance demand.
Composer is used for builds, but no security scanning tools were detected. The missing scanning is a hygiene gap, not by itself evidence that the package is unsafe.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it is less important than the much stronger evidence of stalled maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.